CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

CVE-2024-21410

Critical KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

Published: Feb 13, 2024
Modified: Oct 28, 2025
Product: microsoft exchange_server
EPSS: 2.17%
View Details
7.6

Windows SmartScreen Security Feature Bypass Vulnerability

Published: Feb 13, 2024
Modified: Oct 28, 2025
Product: microsoft windows_10_1507
EPSS: 9.53%
View Details
9.8

CVE-2024-21762

Critical KEV

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker…

Published: Feb 09, 2024
Modified: Oct 24, 2025
Product: fortinet fortiproxy
EPSS: 92.91%
View Details
8.2

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Published: Jan 31, 2024
Modified: Oct 30, 2025
Product: ivanti policy_secure
EPSS: 94.32%
View Details
7.8

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error…

Published: Jan 31, 2024
Modified: Oct 27, 2025
Product: linux linux_kernel
EPSS: 85.97%
View Details
8.8

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

Published: Jan 23, 2024
Modified: Nov 05, 2025
Product: apple ipados
EPSS: 0.22%
View Details
5.3

CVE-2024-0769

Medium KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to…

Published: Jan 21, 2024
Modified: Oct 30, 2025
Product: dlink dir-859_firmware
EPSS: 68.92%
View Details
8.2

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

Published: Jan 17, 2024
Modified: Oct 24, 2025
Product: citrix netscaler_application_delivery_controller
EPSS: 77.01%
View Details
5.5

CVE-2023-6548

Medium KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

Published: Jan 17, 2024
Modified: Oct 24, 2025
Product: citrix netscaler_application_delivery_controller
EPSS: 6.51%
View Details
8.8

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Published: Jan 16, 2024
Modified: Oct 24, 2025
Product: google chrome
EPSS: 0.47%
View Details
9.8

CVE-2023-22527

Critical KEV

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as…

Published: Jan 16, 2024
Modified: Oct 24, 2025
Product: atlassian confluence_data_center
EPSS: 94.36%
View Details
9.1

CVE-2024-21887

Critical KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

Published: Jan 12, 2024
Modified: Oct 31, 2025
Product: ivanti policy_secure
EPSS: 94.41%
View Details
8.2

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

Published: Jan 12, 2024
Modified: Oct 31, 2025
Product: ivanti policy_secure
EPSS: 94.37%
View Details
7.0

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have…

Published: Jan 09, 2024
Modified: Oct 23, 2025
Product: apple iphone_os
EPSS: 0.13%
View Details
5.3

CVE-2022-2586

Medium KEV

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

Published: Jan 08, 2024
Modified: Oct 28, 2025
Product: linux linux_kernel
EPSS: 2.87%
View Details
7.2

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

Published: Aug 03, 2023
Modified: Jan 14, 2026
EPSS: 92.72%
View Details
8.6

The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a…

Published: Jun 23, 2023
Modified: Jan 13, 2026
Product: apple safari
EPSS: 0.25%
View Details
8.8

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

Published: Mar 06, 2023
Modified: Nov 18, 2025
Product: webkitgtk webkitgtk
EPSS: 7.84%
View Details
8.8

Windows Scripting Languages Remote Code Execution Vulnerability

Published: Nov 09, 2022
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 39.24%
View Details
7.8

Windows COM+ Event System Service Elevation of Privilege Vulnerability

Published: Oct 11, 2022
Modified: Jan 13, 2026
Product: microsoft windows_10_1507
EPSS: 0.89%
View Details
7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Published: Sep 13, 2022
Modified: Jan 13, 2026
Product: microsoft windows_10_1507
EPSS: 14.88%
View Details
9.8

CVE-2022-37055

Critical KEV

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

Published: Aug 28, 2022
Modified: Dec 10, 2025
Product: dlink go-rt-ac750_firmware
EPSS: 70.21%
View Details
9.8

CVE-2022-26138

Critical KEV

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content…

Published: Jul 20, 2022
Modified: Jan 14, 2026
Product: atlassian questions_for_confluence
EPSS: 94.32%
View Details
9.8

CVE-2022-26871

Critical KEV

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

Published: Mar 29, 2022
Modified: Dec 22, 2025
Product: trendmicro apex_one
EPSS: 15.28%
View Details