87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 501–550 of 1,734 in KEV · page 11 of 35

IDTitleSummary
CVE-2024-20439Cisco Smart Licensing Utility Static Credential Vulnerability
KEVCisco
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and ga…
CVE-2024-20399Cisco NX-OS Command Injection Vulnerability
KEVCisco
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute command…
CVE-2024-20359Cisco ASA and FTD Privilege Escalation Vulnerability
KEVCVSS 6.0Cisco
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalati…
CVE-2024-20353Cisco ASA and FTD Denial of Service Vulnerability
KEVCVSS 8.6Cisco
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service con…
CVE-2024-1709ConnectWise ScreenConnect Authentication Bypass Vulnerability
KEVConnectWise
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a n…
CVE-2024-1708ConnectWise ScreenConnect Path Traversal Vulnerability
KEVConnectWise
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and…
CVE-2024-13161Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
KEVIvanti
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13160Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
KEVIvanti
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13159Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
KEVIvanti
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-12987DrayTek Vigor Routers OS Command Injection Vulnerability
KEVDrayTek
DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.…
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
KEVBeyondTrust
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with exis…
CVE-2024-12356BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
KEVBeyondTrust
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to in…
CVE-2024-1212Progress Kemp LoadMaster OS Command Injection Vulnerability
KEVCVSS 10.0Progress
Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMa…
CVE-2024-11680ProjectSend Improper Authentication Vulnerability
KEVCVSS 9.8ProjectSend
ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the applica…
CVE-2024-11667Zyxel Multiple Firewalls Path Traversal Vulnerability
KEVCVSS 7.5Zyxel
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a …
CVE-2024-11182MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
KEVMDaemon
MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail mes…
CVE-2024-11120GeoVision Devices OS Command Injection Vulnerability
KEVGeoVision
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system …
CVE-2024-1086Linux Kernel Use-After-Free Vulnerability
KEVCVSS 7.8Linux
Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation.
CVE-2024-0769 D-Link DIR-859 Router Path Traversal Vulnerability
KEVD-Link
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument …
CVE-2024-0519Google Chromium V8 Out-of-Bounds Memory Access Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a craf…
CVE-2024-0012Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
KEVCVSS 9.8Palo Alto Networks
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewall…
CVE-2023-7101Spreadsheet::ParseExcel Remote Code Execution Vulnerability
KEVSpreadsheet::ParseExcel
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, th…
CVE-2023-7028GitLab Community and Enterprise Editions Improper Access Control Vulnerability
KEVGitLab
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent …
CVE-2023-7024Google Chromium WebRTC Heap Buffer Overflow Vulnerability
KEVGoogle
Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a…
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
KEVCitrix
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtua…
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
KEVCitrix
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interfa…
CVE-2023-6448Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
KEVUnitronics
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
CVE-2023-6345Google Skia Integer Overflow Vulnerability
KEVGoogle
Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform…
CVE-2023-5631Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
KEVRoundcube
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
CVE-2023-5217Google Chromium libvpx Heap Buffer Overflow Vulnerability
KEVGoogle
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a…
CVE-2023-52163Digiever DS-2105 Pro Missing Authorization Vulnerability
KEVDigiever
Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
CVE-2023-50224TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
KEVCVSS 6.5TP-Link
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the…
CVE-2023-49897FXC AE1021, AE1021PE OS Command Injection Vulnerability
KEVFXC
FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
KEVCVSS 9.4Citrix
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gatewa…
CVE-2023-4911GNU C Library Buffer Overflow Vulnerability
KEVGNU
GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacke…
CVE-2023-49105ownCloud Improper Authentication Vulnerability
KEVCVSS 9.8ownCloud
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username…
CVE-2023-49103ownCloud graphapi Information Disclosure Vulnerability
KEVownCloud
ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrat…
CVE-2023-48788Fortinet FortiClient EMS SQL Injection Vulnerability
KEVFortinet
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted …
CVE-2023-4863Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
KEVGoogle
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted H…
CVE-2023-48365Qlik Sense HTTP Tunneling Vulnerability
KEVQlik
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the …
CVE-2023-4762Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affe…
CVE-2023-47565QNAP VioStor NVR OS Command Injection Vulnerability
KEVQNAP
QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.
CVE-2023-47246SysAid Server Path Traversal Vulnerability
KEVCVSS 9.8SysAid
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
CVE-2023-46805Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
KEVCVSS 8.2Ivanti
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web…
CVE-2023-46748F5 BIG-IP Configuration Utility SQL Injection Vulnerability
KEVF5
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP managem…
CVE-2023-46747F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
KEVF5
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow a…
CVE-2023-46604Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
KEVApache
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell comman…
CVE-2023-45727North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
KEVNorth Grid
North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which …
CVE-2023-45249Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
KEVAcronis
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
CVE-2023-44487HTTP/2 Rapid Reset Attack Vulnerability
KEVCVSS 7.5IETF
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.