CVE Scouter

Showing 50 of 374327 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2025-48384HIGH8.10.0283958.39YesNo2025-08-252025-08-25cisa.gov, euvdGit contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files…Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2021-33771HIGH7.80.0625558.39YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-3388HIGH7.20.8446158.36NoNo2023-06-242026-04-08euvdThe Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in v…The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A partial patch was made available in 2.10.1 and the issue was fully patched in 2.10.2.
CVE-2022-34169HIGH7.50.8103958.36NoNo2022-07-192026-05-27euvdThe Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used…The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
CVE-2013-5223MEDIUM5.40.3356758.35YesNo2022-03-252022-03-25cisa.gov, euvdA cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary w…A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
CVE-2019-1069HIGH7.80.0611758.34YesNo2022-03-152022-03-15cisa.gov, euvdA privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
CVE-2025-24990HIGH7.80.0600358.3YesYes2025-10-142025-10-14cisa.gov, euvd, githubMicrosoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attack…Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.
CVE-2025-0107HIGH7.70.7853258.29NoNo2025-01-112025-01-24euvdAn OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as t…An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
CVE-2022-24422CRITICAL9.60.5679658.28NoNo2022-05-262024-09-16euvdDell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticate…Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.
CVE-2024-11972CRITICAL9.80.5447558.27NoNo2024-12-312024-12-31euvdThe Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to …The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.
CVE-2023-36563MEDIUM6.50.2071958.25YesNo2023-10-102023-10-10cisa.gov, euvdMicrosoft WordPad contains an unspecified vulnerability that allows for information disclosure.Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.
CVE-2018-6882MEDIUM6.10.2523158.23YesNo2022-04-192022-04-19cisa.gov, euvdSynacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary…Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2018-0175HIGH8.00.0350158.23YesNo2022-03-032022-03-03cisa.gov, euvdFormat string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IO…Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
CVE-2026-3502HIGH7.80.057558.21YesNo2026-04-022026-04-02cisa.gov, euvdTrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery …TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
CVE-2016-0167HIGH7.80.0572958.21YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted applicationMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
CVE-2024-30044HIGH7.20.839958.2NoNo2024-05-142025-05-03euvdMicrosoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-30051HIGH7.80.0568758.19YesNo2024-05-142024-05-14cisa.gov, euvdMicrosoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
CVE-2021-23874HIGH8.20.0102658.16YesNo2021-11-032021-11-03cisa.gov, euvdMcAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges a…McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.
CVE-2022-32917HIGH7.80.0560358.16YesNo2022-09-142022-09-14cisa.gov, euvdApple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute…Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges.
CVE-2024-44309MEDIUM6.30.2272858.15YesNo2024-11-212024-11-21cisa.gov, euvdApple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lea…Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.
CVE-2023-21823HIGH7.80.0556358.15YesNo2023-02-142023-02-14cisa.gov, euvdMicrosoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
CVE-2025-22225HIGH8.20.0099758.15YesNo2025-03-042025-03-04cisa.gov, euvd, nvdVMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to …VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
CVE-2023-36756HIGH8.00.7467158.13NoNo2023-09-122025-10-30euvdMicrosoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-0492HIGH7.80.0552858.13YesNo2026-06-022026-06-02cisa.gov, euvdLinux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent f…Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CVE-2023-38095HIGH8.80.6551758.13NoNo2024-05-032024-09-18euvdNETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerabi…NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19717.
CVE-2018-15473MEDIUM5.90.9863158.12NoYes2018-08-172025-12-17euvd, githubOpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after …OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
CVE-2020-17087HIGH7.80.0543158.1YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-43795HIGH8.60.6771558.1NoNo2023-10-242024-09-17euvdGeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Serv…GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.
CVE-2021-39843HIGH7.80.7667858.04NoNo2021-09-292024-09-17euvdAcrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an ou…Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2021-27651CRITICAL9.80.5384158.04NoNo2021-04-292024-08-03euvdIn versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentica…In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
CVE-2023-32645CRITICAL9.80.5381258.03NoNo2023-10-112025-11-04euvdA leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted ne…A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.
CVE-2022-36094HIGH8.90.6409858.03NoNo2022-09-082025-04-22euvdXWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to…XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3RC1. As a workaround, it is possible to replace `viewattachrev.vm`, the entry point for this attack, by a patched version from the patch without updating XWiki.
CVE-2023-46727HIGH8.60.6750158.03NoNo2023-12-132024-11-19euvdGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint ca…GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.
CVE-2024-39931CRITICAL9.90.5265858.03NoNo2024-07-042024-08-02euvdGogs through 0.13.0 allows deletion of internal files.Gogs through 0.13.0 allows deletion of internal files.
CVE-2019-0863HIGH7.80.0520758.02YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code exe…Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
CVE-2021-30900HIGH7.80.0520458.02YesNo2023-03-302023-03-30cisa.gov, euvdApple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application t…Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.
CVE-2015-6175HIGH7.80.0516958.01YesNo2022-05-252022-05-25cisa.gov, euvdThe kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
CVE-2024-23917CRITICAL9.80.537358.01NoNo2024-02-062024-08-01euvdIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
CVE-2026-18556HIGH7.40.0049257.97YesYes2026-08-012026-08-05cisa.gov, euvd, github, nvdAuthentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects…Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
CVE-2021-37976MEDIUM6.50.1990157.97YesNo2021-11-032021-11-03cisa.gov, euvdGoogle Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain po…Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2021-27273HIGH8.80.6499757.95NoNo2021-03-292024-08-03euvdThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System …This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the SettingConfigController class. When parsing the fileName parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12121.
CVE-2009-1123HIGH7.80.0491857.92YesNo2022-03-032022-03-03cisa.gov, euvdThe kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privilege…The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
CVE-2024-9441CRITICAL9.80.5347257.92NoNo2024-10-022024-10-02euvdThe Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated att…The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
CVE-2026-28318HIGH7.50.0835157.92YesNo2026-06-052026-06-05cisa.gov, euvd, nvdSolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-…SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
CVE-2022-0513CRITICAL9.80.534657.91NoNo2022-02-162025-02-10euvdThe WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason …The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.
CVE-2002-0367HIGH7.80.0487957.91YesNo2022-03-032022-03-03cisa.gov, euvdsmss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local…smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
CVE-2023-0266HIGH7.90.0370257.9YesNo2023-03-302023-03-30cisa.gov, euvdLinux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.
CVE-2025-34300CRITICAL10.00.510857.88NoNo2025-07-162026-05-26euvdA template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwwe…A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
CVE-2022-0218HIGH8.30.7051157.88NoNo2022-02-042025-02-10euvdThe WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme s…The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.
CVE-2018-0156HIGH7.50.0819557.87YesNo2022-03-032022-03-03cisa.gov, euvdA vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker…A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.