CVE Scouter

Showing 50 of 374329 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2021-36742HIGH7.80.0148256.72YesNo2021-11-032021-11-03cisa.gov, euvdTrend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows…Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
CVE-2023-20963HIGH7.80.0146556.71YesNo2023-04-132023-04-13cisa.gov, euvdAndroid Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK wi…Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.
CVE-2023-36824HIGH7.40.7742256.7NoNo2023-07-112025-02-13euvdRedis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of argume…Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command and a list of arguments may, in some cases, trigger a heap overflow and result in reading random heap memory, heap corruption and potentially remote code execution. Several scenarios that may lead to authenticated users executing a specially crafted `COMMAND GETKEYS` or `COMMAND GETKEYSANDFLAGS`and authenticated users who were set with ACL rules that match key names, executing a specially crafted command that refers to a variadic list of key names. The vulnerability is patched in Redis 7.0.12.
CVE-2019-1214HIGH7.80.0141956.7YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.
CVE-2023-41974HIGH7.80.014156.69YesNo2026-03-052026-03-05cisa.gov, euvdApple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
CVE-2024-23296HIGH7.80.0141156.69YesNo2024-03-062024-03-06cisa.gov, euvdApple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel re…Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
CVE-2025-21335HIGH7.80.0136356.68YesNo2025-01-142025-01-14cisa.gov, euvdMicrosoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM priv…Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2024-8275CRITICAL9.80.4991456.67NoNo2024-09-252026-04-08euvdThe The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function…The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.
CVE-2023-41990HIGH7.80.0134756.67YesNo2024-01-082024-01-08cisa.gov, euvdApple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.
CVE-2026-20700HIGH7.80.0131956.66YesNo2026-02-122026-02-12cisa.gov, cnvd, euvdApple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerabili…Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
CVE-2023-6018CRITICAL10.00.4759456.66NoNo2023-11-162024-08-02euvdAn attacker can overwrite any file on the server hosting MLflow without any authentication.An attacker can overwrite any file on the server hosting MLflow without any authentication.
CVE-2023-46347CRITICAL9.80.4988556.66NoNo2023-10-252024-09-11euvdIn the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform S…In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVE-2025-32701HIGH7.80.0129756.65YesNo2025-05-132025-05-13cisa.gov, euvdMicrosoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate…Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2020-0069HIGH7.80.0129956.65YesNo2021-11-032021-11-03cisa.gov, euvdMultiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue…Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
CVE-2025-38352HIGH7.80.012556.64YesYes2025-09-042025-09-04cisa.gov, euvd, nvd, packetstormLinux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity…Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2022-41800HIGH8.70.6240656.64NoNo2022-12-072025-04-23euvdIn all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appli…In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-40552CRITICAL9.80.4973456.61NoNo2026-01-282026-02-27euvdSolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious ac…SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
CVE-2018-15439CRITICAL9.80.4974256.61NoNo2018-11-082024-11-26euvdA vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authenticat…A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.
CVE-2022-42827HIGH7.80.0113656.6YesNo2022-10-252022-10-25cisa.gov, euvdApple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kerne…Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges.
CVE-2017-17485CRITICAL9.80.4972756.6NoNo2018-01-102025-08-27euvdFasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix …FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
CVE-2022-22706HIGH7.80.0109556.58YesYes2023-03-302023-03-30cisa.gov, euvd, githubArm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memo…Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.
CVE-2026-21385HIGH7.80.0106956.57YesNo2026-03-032026-03-03cisa.gov, euvdMultiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
CVE-2023-42824HIGH7.80.0094356.53YesNo2023-10-052023-10-05cisa.gov, euvdApple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.
CVE-2022-38421HIGH7.20.7921856.53NoNo2022-10-142025-04-23euvdAdobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restr…Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.
CVE-2021-27059HIGH7.60.0318256.51YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Office contains an unspecified vulnerability that allows for remote code execution.Microsoft Office contains an unspecified vulnerability that allows for remote code execution.
CVE-2025-5394CRITICAL9.80.4946556.51NoNo2025-07-152026-04-08euvdThe Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing cap…The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution. CVE-2025-54019 is likely a duplicate of this.
CVE-2023-6360HIGH8.60.6314156.5NoNo2023-11-302024-10-10euvdThe 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' pa…The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
CVE-2020-9859HIGH7.80.0082956.49YesNo2021-11-032021-11-03cisa.gov, euvdApple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel p…Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
CVE-2023-2249HIGH8.80.6080956.48NoNo2023-06-092026-04-08euvdThe wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions…The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.
CVE-2021-1048HIGH7.80.0078356.47YesNo2022-05-232022-05-23cisa.gov, euvdAndroid kernel contains a use-after-free vulnerability that allows for privilege escalation.Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2021-39793HIGH7.80.0073856.46YesNo2022-04-112022-04-11cisa.gov, euvdGoogle Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.
CVE-2023-33063HIGH7.80.00756.45YesNo2023-12-052023-12-05cisa.gov, euvdMultiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to…Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2019-8526HIGH7.80.0070156.45YesNo2023-04-172023-04-17cisa.gov, euvdApple macOS contains a use-after-free vulnerability that could allow for privilege escalation.Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.
CVE-2022-26904HIGH7.00.0981756.44YesNo2022-04-252022-04-25cisa.gov, euvdMicrosoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-32986HIGH8.80.6068356.44NoNo2023-05-162025-01-23euvdJenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File …Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
CVE-2025-54313HIGH7.50.0411256.44YesNo2026-01-222026-01-22cisa.gov, euvdPrettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js fil…Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2024-43047HIGH7.80.0067456.44YesNo2024-10-082024-10-08cisa.gov, euvdMultiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of …Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
CVE-2024-29748HIGH7.80.006856.44YesNo2024-04-042024-04-04cisa.gov, euvdAndroid Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin…Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
CVE-2022-25305HIGH7.20.7890556.42NoNo2022-02-242025-02-07euvdThe WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter f…The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.
CVE-2022-37109CRITICAL9.80.4920156.42NoNo2022-11-142025-05-01euvdpatrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to …patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the Tornado rule to throw a 403 error when password.txt is accessed can be bypassed. Furthermore, it is not necessary to crack the password hash to authenticate with the application because the password hash is also used as the cookie secret, so an attacker can generate his own authentication cookie.
CVE-2022-36096HIGH8.90.594756.41NoNo2022-09-082025-04-23euvdThe XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic w…The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted attachments index with an attachment containing javascript in its name. This issue has been patched in XWiki 13.10.6 and 14.3. As a workaround, modify fix the vulnerability by editing the wiki page `XWiki.DeletedAttachments` with the object editor, open the `JavaScriptExtension` object and apply on the content the changes that can be found on the fix commit.
CVE-2024-46909CRITICAL9.80.4917156.41NoNo2024-12-022024-12-02euvdIn WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in th…In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
CVE-2024-27921HIGH8.80.6058556.4NoNo2024-03-212025-04-10euvdGrav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the applicati…Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc. This critical security flaw poses severe risks, that can allow attackers to inject arbitrary code on the server, undermine integrity of backup files by overwriting existing files or creating new ones, and exfiltrate sensitive data using CSS exfiltration techniques. Upgrading to patched version 1.7.45 can mitigate the issue.
CVE-2023-6895MEDIUM6.30.8913856.4NoNo2023-12-172024-11-21euvdA vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vuln…A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.
CVE-2019-7483HIGH7.50.0397756.39YesNo2022-03-282022-03-28cisa.gov, euvdIn SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the prese…In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CVE-2021-29492HIGH8.10.6838356.33NoNo2021-05-282024-08-03euvdEnvoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versio…Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e.g. `/something%2F..%2Fadmin`, to bypass access control, e.g. a block on `/admin`. A backend server could then decode slash sequences and normalize path and provide an attacker access beyond the scope provided for by the access control policy. ### Impact Escalation of Privileges when using RBAC or JWT filters with enforcement based on URL path. Users with back end servers that interpret `%2F` and `/` and `%5C` and `\` interchangeably are impacted. ### Attack Vector URL paths containing escaped slash characters delivered by untrusted client. Patches in versions 1.18.3, 1.17.3, 1.16.4, 1.15.5 contain new path normalization option to decode escaped slash characters. As a workaround, if back end servers treat `%2F` and `/` and `%5C` and `\` interchangeably and a URL path based access control is configured, one may reconfigure the back end server to not treat `%2F` and `/` and `%5C` and `\` interchangeably.
CVE-2025-43510HIGH7.80.0036256.33YesNo2026-03-202026-03-20cisa.gov, euvdApple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to …Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CVE-2022-32174CRITICAL9.00.5802156.31NoNo2022-10-112025-05-16euvdIn Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CVE-2021-31010HIGH7.50.0367356.29YesNo2022-08-252022-08-25cisa.gov, euvdIn affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
CVE-2025-48572HIGH7.80.0025356.29YesNo2025-12-022025-12-02cisa.gov, cnvd, euvdAndroid Framework contains an unspecified vulnerability that allows for privilege escalation.Android Framework contains an unspecified vulnerability that allows for privilege escalation.