CVE Scouter

Showing 50 of 374236 · Home · API docs
IDCVE identifier (e.g. CVE-2024-3094). SeverityQualitative severity from the source (CRITICAL / HIGH / MEDIUM / LOW). CVSSCommon Vulnerability Scoring System base score (0–10). Higher = more severe. EPSSFIRST Exploit Prediction Scoring System (0–1). Estimated chance of exploitation in the next ~30 days. RiskCVE Scouter triage score (0–100) from CVSS + EPSS + KEV. Higher = patch sooner. KEVYes if listed in CISA's Known Exploited Vulnerabilities catalog (actively exploited). PoCYes if PacketStorm (or other PoC sources) listed a public exploit / PoC for this CVE. PublishedDate the advisory / CVE was first published. ModifiedDate the record was last updated in our sources. SourcesFeeds that contributed to this record (nvd, cnvd, euvd, cisa.gov, packetstorm, github, …). DescriptionShort summary of the vulnerability. Hover the text for the full description.
CVE-2013-0629HIGH7.50.6590278.07YesNo2022-03-072022-03-07cisa.gov, euvdAdobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
CVE-2023-29552HIGH7.50.6587378.06YesNo2023-11-082023-11-08cisa.gov, euvdThe Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to…The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
CVE-2013-0631HIGH7.50.6586778.05YesNo2022-03-072022-03-07cisa.gov, euvdAdobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
CVE-2023-6549HIGH8.20.5763377.97YesNo2024-01-172024-01-17cisa.gov, euvdCitrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a …Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2023-49897HIGH8.80.5072977.96YesNo2023-12-212023-12-21cisa.gov, euvdFXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.
CVE-2019-3568CRITICAL9.80.3916677.91YesNo2022-04-192022-04-19cisa.gov, euvdA buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a …A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
CVE-2016-11021HIGH7.20.688777.9YesNo2022-03-252022-03-25cisa.gov, euvdsetSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
CVE-2023-41763MEDIUM5.30.9035377.82YesNo2023-10-102023-10-10cisa.gov, euvdMicrosoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.
CVE-2023-21608HIGH7.80.6147577.72YesNo2023-10-102023-10-10cisa.gov, euvdAdobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
CVE-2013-0431MEDIUM5.30.8998777.7YesNo2022-05-252022-05-25cisa.gov, euvdUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sand…Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
CVE-2021-3493HIGH8.80.4916677.41YesYes2022-10-202022-10-20cisa.gov, euvd, packetstormThe overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, …The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.
CVE-2019-13720HIGH8.80.491477.4YesNo2022-05-232022-05-23cisa.gov, euvdGoogle Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a cr…Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2023-5217HIGH8.80.4901377.35YesNo2023-10-022023-10-02cisa.gov, euvdGoogle Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit he…Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
CVE-2020-8655HIGH7.80.6007577.23YesNo2021-11-032021-11-03cisa.gov, euvdEyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scrip…EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.
CVE-2021-38163CRITICAL9.90.3601877.21YesNo2022-06-092022-06-09cisa.gov, euvdSAP NetWeaver contains a vulnerability that allows unrestricted file upload.SAP NetWeaver contains a vulnerability that allows unrestricted file upload.
CVE-2020-16009HIGH8.80.4857477.2YesNo2021-11-032021-11-03cisa.gov, euvdGoogle Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a…Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2019-8394HIGH7.50.6333677.17YesNo2021-11-032021-11-03cisa.gov, euvdZoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page custo…Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
CVE-2017-11774HIGH7.80.5989377.16YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitat…Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.
CVE-2006-2492HIGH8.80.4838777.14YesNo2022-06-082022-06-08cisa.gov, euvdMicrosoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.
CVE-2024-21338HIGH7.80.598177.13YesNo2024-02-132026-07-31cisa.gov, euvd, nvdWindows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability
CVE-2021-20016CRITICAL9.80.3695277.13YesNo2021-11-032021-11-03cisa.gov, euvdSonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated a…SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
CVE-2022-28810MEDIUM6.80.7096677.04YesNo2023-03-072023-03-07cisa.gov, euvdZoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password cha…Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.
CVE-2016-1646HIGH8.80.481177.04YesNo2022-06-082022-06-08cisa.gov, euvdGoogle Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibl…Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2019-19006CRITICAL9.80.3661577.02YesNo2026-02-032026-02-03cisa.gov, euvdSangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authenticati…Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.
CVE-2020-13965MEDIUM6.30.7659677.01YesNo2024-06-262024-06-26cisa.gov, euvdRoundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML a…Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
CVE-2021-21973MEDIUM5.30.8801277.0YesNo2022-03-072022-03-07cisa.gov, euvdVMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin…VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
CVE-2025-2775CRITICAL9.30.4224476.99YesNo2025-07-222025-07-22cisa.gov, euvdSysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allo…SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
CVE-2024-30088HIGH7.00.6820276.87YesNo2024-06-112026-08-04cisa.gov, euvd, nvdWindows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability
CVE-2010-1428HIGH7.50.6230876.81YesNo2022-05-252022-05-25cisa.gov, euvdUnauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this blo…Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
CVE-2022-31199CRITICAL9.80.3600976.8YesNo2023-07-112023-07-11cisa.gov, euvdNetwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthen…Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.
CVE-2014-4123HIGH8.80.4725976.74YesNo2022-05-252022-05-25cisa.gov, euvdMicrosoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
CVE-2009-0557HIGH7.80.5855176.69YesNo2022-06-082022-06-08cisa.gov, euvdMicrosoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file wi…Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
CVE-2016-7262HIGH7.80.5820476.57YesNo2022-03-032022-03-03cisa.gov, euvdA security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vu…A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
CVE-2025-0411HIGH7.00.6707176.47YesNo2025-02-062025-02-06cisa.gov, euvd7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to e…7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2016-7193HIGH7.80.5770576.4YesNo2022-03-032022-03-03cisa.gov, euvdMicrosoft Office contains a memory corruption vulnerability which can allow for remote code execution.Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.
CVE-2017-0101HIGH7.80.5748276.32YesNo2022-03-152022-03-15cisa.gov, euvdA privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
CVE-2010-5330CRITICAL9.80.3464176.32YesNo2022-04-152022-04-15cisa.gov, euvdCertain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
CVE-2026-60137MEDIUM5.90.7902976.26YesYes2026-07-172026-07-29cisa.gov, euvd, github, nvd, packetstormWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query…WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVE-2023-35081HIGH7.20.6357776.05YesNo2023-07-312023-07-31cisa.gov, euvdIvanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicio…Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).
CVE-2024-29988HIGH8.80.4515176.0YesNo2024-04-302024-04-30cisa.gov, euvdMicrosoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) f…Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
CVE-2024-57968CRITICAL9.90.3251475.98YesNo2025-03-102025-03-10cisa.gov, euvdAdvantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unint…Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
CVE-2023-5631MEDIUM6.10.7587375.96YesNo2023-10-262023-10-26cisa.gov, euvdRoundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript c…Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.
CVE-2015-2425HIGH8.80.4485175.9YesNo2022-05-252022-05-25cisa.gov, euvdMicrosoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-servi…Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2020-2509CRITICAL9.80.3338175.88YesNo2022-04-112022-04-11cisa.gov, euvdQNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
CVE-2015-1701HIGH7.80.56275.87YesNo2022-03-032022-03-03cisa.gov, euvdAn unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute…An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
CVE-2015-2419HIGH8.80.4468875.84YesNo2022-03-282022-03-28cisa.gov, euvdJScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a…JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2023-36847MEDIUM5.30.8457375.8YesNo2023-11-132023-11-13cisa.gov, euvdJuniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-…Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.
CVE-2024-9380HIGH7.20.6278575.77YesNo2024-10-092024-10-09cisa.gov, euvdIvanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authen…Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.
CVE-2021-33742HIGH7.50.5913975.7YesNo2021-11-032021-11-03cisa.gov, euvdMicrosoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
CVE-2019-17026HIGH8.80.4367775.49YesNo2021-11-032021-11-03cisa.gov, euvdMozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when…Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.