Search Results (15541 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-27098 1 Glpi-project 1 Glpi 2025-01-02 6.4 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13.
CVE-2023-36012 1 Microsoft 9 Windows Server 2008, Windows Server 2008 R2, Windows Server 2008 Sp2 and 6 more 2025-01-01 5.3 Medium
DHCP Server Service Information Disclosure Vulnerability
CVE-2023-35333 1 Microsoft 2 Media Wiki Extensions Pandoc Upload, Pandocupload 2025-01-01 8.8 High
MediaWiki PandocUpload Extension Remote Code Execution Vulnerability
CVE-2023-35326 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 8 more 2025-01-01 5.5 Medium
Windows CDP User Components Information Disclosure Vulnerability
CVE-2023-35325 1 Microsoft 16 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 13 more 2025-01-01 7.5 High
Windows Print Spooler Information Disclosure Vulnerability
CVE-2023-32042 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-01-01 6.5 Medium
OLE Automation Information Disclosure Vulnerability
CVE-2023-32041 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2025-01-01 5.5 Medium
Windows Update Orchestrator Service Information Disclosure Vulnerability
CVE-2023-29367 1 Microsoft 5 Windows Server 2012, Windows Server 2012 R2, Windows Server 2016 and 2 more 2025-01-01 7.8 High
iSCSI Target WMI Provider Remote Code Execution Vulnerability
CVE-2023-21569 1 Microsoft 1 Azure Devops Server 2025-01-01 5.5 Medium
Azure DevOps Server Spoofing Vulnerability
CVE-2023-21553 1 Microsoft 1 Azure Devops Server 2025-01-01 7.5 High
Azure DevOps Server Remote Code Execution Vulnerability
CVE-2023-21761 1 Microsoft 1 Exchange Server 2025-01-01 7.5 High
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2023-21753 1 Microsoft 3 Windows 10, Windows 10 1809, Windows Server 2019 2025-01-01 5.5 Medium
Event Tracing for Windows Information Disclosure Vulnerability
CVE-2024-38183 1 Microsoft 1 Groupme 2024-12-31 9.8 Critical
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
CVE-2024-43469 1 Microsoft 1 Azure Cyclecloud 2024-12-31 8.8 High
Azure CycleCloud Remote Code Execution Vulnerability
CVE-2024-43458 1 Microsoft 2 Windows 10 1607, Windows Server 2016 2024-12-31 7.7 High
Windows Networking Information Disclosure Vulnerability
CVE-2024-38260 1 Microsoft 9 Windows Server 2008, Windows Server 2008 R2, Windows Server 2012 and 6 more 2024-12-31 8.8 High
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38257 1 Microsoft 17 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 14 more 2024-12-31 7.5 High
Microsoft AllJoyn API Information Disclosure Vulnerability
CVE-2024-38256 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2024-12-31 5.5 Medium
Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2024-38254 1 Microsoft 20 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 17 more 2024-12-31 5.5 Medium
Windows Authentication Information Disclosure Vulnerability
CVE-2023-34251 1 Getgrav 1 Grav 2024-12-27 10 Critical
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains a fix for this issue.