Search Results (15543 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-35326 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 8 more 2025-01-01 5.5 Medium
Windows CDP User Components Information Disclosure Vulnerability
CVE-2023-35325 1 Microsoft 16 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 13 more 2025-01-01 7.5 High
Windows Print Spooler Information Disclosure Vulnerability
CVE-2023-32042 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-01-01 6.5 Medium
OLE Automation Information Disclosure Vulnerability
CVE-2023-32041 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2025-01-01 5.5 Medium
Windows Update Orchestrator Service Information Disclosure Vulnerability
CVE-2023-29367 1 Microsoft 5 Windows Server 2012, Windows Server 2012 R2, Windows Server 2016 and 2 more 2025-01-01 7.8 High
iSCSI Target WMI Provider Remote Code Execution Vulnerability
CVE-2023-21569 1 Microsoft 1 Azure Devops Server 2025-01-01 5.5 Medium
Azure DevOps Server Spoofing Vulnerability
CVE-2023-21553 1 Microsoft 1 Azure Devops Server 2025-01-01 7.5 High
Azure DevOps Server Remote Code Execution Vulnerability
CVE-2023-21761 1 Microsoft 1 Exchange Server 2025-01-01 7.5 High
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2023-21753 1 Microsoft 3 Windows 10, Windows 10 1809, Windows Server 2019 2025-01-01 5.5 Medium
Event Tracing for Windows Information Disclosure Vulnerability
CVE-2024-38183 1 Microsoft 1 Groupme 2024-12-31 9.8 Critical
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
CVE-2024-43469 1 Microsoft 1 Azure Cyclecloud 2024-12-31 8.8 High
Azure CycleCloud Remote Code Execution Vulnerability
CVE-2024-43458 1 Microsoft 2 Windows 10 1607, Windows Server 2016 2024-12-31 7.7 High
Windows Networking Information Disclosure Vulnerability
CVE-2024-38260 1 Microsoft 9 Windows Server 2008, Windows Server 2008 R2, Windows Server 2012 and 6 more 2024-12-31 8.8 High
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38257 1 Microsoft 17 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 14 more 2024-12-31 7.5 High
Microsoft AllJoyn API Information Disclosure Vulnerability
CVE-2024-38256 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2024-12-31 5.5 Medium
Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2024-38254 1 Microsoft 20 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 17 more 2024-12-31 5.5 Medium
Windows Authentication Information Disclosure Vulnerability
CVE-2023-34251 1 Getgrav 1 Grav 2024-12-27 10 Critical
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains a fix for this issue.
CVE-2024-5466 1 Zohocorp 5 Manageengine Opmanager, Manageengine Opmanager Msp, Manageengine Opmanager Plus and 2 more 2024-12-19 8.8 High
Zohocorp ManageEngine OpManager andĀ Remote Monitoring and Management versionsĀ 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
CVE-2024-9717 1 Trimble 1 Sketchup Viewer 2024-12-19 7.8 High
Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24101.
CVE-2024-12665 1 Ruifang-tech 1 Rebuild 2024-12-19 3.5 Low
A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown function of the component Task Comment Attachment Upload. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.