CVE Scouter

Showing 50 of 374327 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2023-27823CRITICAL9.80.5331257.86NoNo2023-05-122026-07-09euvdAn authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
CVE-2019-0543HIGH7.80.0471857.85YesNo2022-03-152022-03-15cisa.gov, euvdA privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited …A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
CVE-2022-42904HIGH7.20.8296357.84NoNo2022-11-182025-04-30euvdZoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
CVE-2019-7287HIGH7.80.0458957.81YesNo2022-05-232022-05-23cisa.gov, euvdApple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.
CVE-2025-60710HIGH7.80.0459857.81YesNo2026-04-132026-04-13cisa.gov, euvdMicrosoft Windows contains a link following vulnerability that allows for privilege escalationMicrosoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2020-1027HIGH7.80.0454757.79YesNo2022-05-232022-05-23cisa.gov, euvdAn elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully ex…An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
CVE-2024-6396CRITICAL9.80.5311357.79NoNo2024-07-122024-08-01euvdA vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host serve…A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.
CVE-2024-48766HIGH8.60.6676157.77NoNo2025-05-132025-05-13euvdNetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors r…NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.
CVE-2018-19953MEDIUM6.10.2389457.76YesNo2022-05-242022-05-24cisa.gov, euvdA cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2026-10523CRITICAL9.90.518757.75NoNo2026-06-092026-06-10euvd, nvdAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthent…An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
CVE-2021-38646HIGH7.80.04457.74YesNo2022-03-282022-03-28cisa.gov, euvdMicrosoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
CVE-2023-20889HIGH7.50.7925857.74NoNo2023-06-072025-01-07euvdAria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operatio…Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
CVE-2024-32238CRITICAL9.80.5294857.73NoNo2024-04-222024-08-02euvdH3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management…H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.
CVE-2012-2034HIGH7.50.07857.73YesNo2022-03-282022-03-28cisa.gov, euvdAdobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).
CVE-2022-44149HIGH8.80.6435457.72NoNo2023-01-062025-04-09euvdThe web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in…The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required
CVE-2022-40770HIGH7.20.8252957.69NoNo2022-11-232025-04-28euvdZoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high…Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
CVE-2024-27443MEDIUM6.10.2363257.67YesNo2025-05-192025-05-19cisa.gov, euvdZimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user in…Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.
CVE-2018-8611HIGH7.80.0419657.67YesNo2022-05-242022-05-24cisa.gov, euvdA privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
CVE-2019-0859HIGH7.80.0415157.65YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run …Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2021-30869HIGH7.80.041557.65YesNo2021-11-032021-11-03cisa.gov, euvdApple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with …Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
CVE-2023-36761MEDIUM6.50.1895957.64YesNo2023-09-122023-09-12cisa.gov, euvdMicrosoft Word contains an unspecified vulnerability that allows for information disclosure.Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
CVE-2025-44148CRITICAL9.80.5263157.62NoNo2025-06-032026-07-05euvdCross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx co…Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
CVE-2016-4655MEDIUM5.50.3032257.61YesNo2022-05-242022-05-24cisa.gov, euvdThe Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2024-26169HIGH7.80.0401457.6YesNo2024-06-132024-06-13cisa.gov, euvdMicrosoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user per…Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
CVE-2025-48595HIGH8.00.0171457.6YesNo2026-07-282026-07-27cisa.gov, cnvd, euvd, nvdGoogle Android is a Linux-based open source operating system from the American company Google. Google Android has a privilege escalation vul…Google Android is a Linux-based open source operating system from the American company Google. Google Android has a privilege escalation vulnerability. This vulnerability is caused by an integer overflow in the Framework component. An attacker can use this vulnerability to gain higher privileges on the system.
CVE-2023-39362HIGH7.20.8218657.57NoNo2023-09-052025-02-27euvdCacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated p…Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-12856HIGH7.20.8219257.57NoNo2024-12-272025-11-22euvdThe Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware ver…The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.
CVE-2020-9907HIGH7.80.0387557.56YesNo2022-06-272022-06-27cisa.gov, euvdApple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges…Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
CVE-2026-21533HIGH7.80.0384657.55YesNo2026-02-102026-02-10cisa.gov, euvdMicrosoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to…Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2025-24985HIGH7.80.0384657.55YesNo2025-03-112025-03-11cisa.gov, euvdMicrosoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker …Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.
CVE-2023-36039HIGH8.00.7299257.55NoNo2023-11-142025-10-08euvdMicrosoft Exchange Server Spoofing VulnerabilityMicrosoft Exchange Server Spoofing Vulnerability
CVE-2024-48914CRITICAL9.10.6042957.55NoNo2024-10-152024-10-15euvdVendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin al…Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables, and other critical data stored on the server. In the same code path is an additional vector for crashing the server via a malformed URI. Patches are available in versions 3.0.5 and 2.3.3. Some workarounds are also available. One may use object storage rather than the local file system, e.g. MinIO or S3, or define middleware which detects and blocks requests with urls containing `/../`.
CVE-2006-3730HIGH8.80.6381757.54NoNo2006-07-192026-02-25euvdInteger overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute…Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
CVE-2016-3643HIGH7.80.0370457.5YesNo2021-11-032021-11-03cisa.gov, euvdSolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.
CVE-2019-5591MEDIUM6.50.1856657.5YesNo2021-11-032021-11-03cisa.gov, euvdFortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept s…Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
CVE-2017-12235HIGH7.50.0712857.49YesNo2022-03-032022-03-03cisa.gov, euvdA vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthentic…A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
CVE-2017-12237HIGH7.50.0712857.49YesNo2022-03-032022-03-03cisa.gov, euvdA vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote a…A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.
CVE-2021-30663HIGH7.80.036957.49YesNo2021-11-032021-11-03cisa.gov, euvdApple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing mal…Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
CVE-2017-12234HIGH7.50.0712857.49YesNo2022-03-032022-03-03cisa.gov, euvdThere is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, …There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
CVE-2018-0154HIGH7.50.0711757.49YesNo2022-03-032022-03-03cisa.gov, euvdA vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an una…A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.
CVE-2017-12233HIGH7.50.0712857.49YesNo2022-03-032022-03-03cisa.gov, euvdThere is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, …There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
CVE-2017-12231HIGH7.50.0712857.49YesNo2022-03-032022-03-03cisa.gov, euvdA vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote…A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.
CVE-2022-31126CRITICAL10.00.4993757.48NoNo2022-07-062025-04-23euvdRoxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remo…Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2018-19321HIGH7.80.0367157.48YesNo2022-10-242022-10-24cisa.gov, euvdThe GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functional…The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
CVE-2019-1385HIGH7.80.0362557.47YesNo2022-05-232022-05-23cisa.gov, euvdA privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting …A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
CVE-2023-34468HIGH8.80.6363357.47NoNo2023-06-122025-02-13euvdThe DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authori…The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
CVE-2021-27102HIGH7.80.0362457.47YesNo2021-11-032021-11-03cisa.gov, euvdAccellion FTA contains an OS command injection vulnerability exploited via a local web service call.Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.
CVE-2024-5762HIGH8.10.7159857.46NoNo2024-08-212024-08-21euvdZen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability. The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408.
CVE-2023-46263HIGH7.20.8188457.46NoNo2023-12-192024-08-02euvdAn unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker t…An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
CVE-2018-19320HIGH7.80.0359757.46YesNo2022-10-242022-10-24cisa.gov, euvdThe GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like func…The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.