CVE Database

59526+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4774
6.5 MEDIUM

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-4772
5.9 MEDIUM

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4769
5.9 MEDIUM

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn …

May 14, 2024
CVE-2024-4768
6.1 MEDIUM

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox …

May 14, 2024
CVE-2024-4767
4.3 MEDIUM

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. …

May 14, 2024
CVE-2024-4766
4.3 MEDIUM

Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug …

May 14, 2024
CVE-2024-31488
6.8 MEDIUM

An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through …

May 14, 2024
CVE-2024-30059
6.1 MEDIUM

Microsoft Intune for Android Mobile Application Management Tampering Vulnerability

May 14, 2024
CVE-2024-30054
6.5 MEDIUM

Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30053
6.5 MEDIUM

Azure Migrate Cross-Site Scripting Vulnerability

May 14, 2024
CVE-2024-30050
5.4 MEDIUM

Windows Mark of the Web Security Feature Bypass Vulnerability

May 14, 2024
CVE-2024-30046
5.9 MEDIUM

Visual Studio Denial of Service Vulnerability

May 14, 2024
CVE-2024-30045
6.3 MEDIUM

.NET and Visual Studio Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30043
6.5 MEDIUM

Microsoft SharePoint Server Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30041
5.4 MEDIUM

Microsoft Bing Search Spoofing Vulnerability

May 14, 2024
CVE-2024-30039
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30037
5.5 MEDIUM

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30036
6.5 MEDIUM

Windows Deployment Services Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30034
5.5 MEDIUM

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30021
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30019
6.5 MEDIUM

DHCP Server Service Denial of Service Vulnerability

May 14, 2024
CVE-2024-30016
5.5 MEDIUM

Windows Cryptographic Services Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30012
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30011
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

May 14, 2024
CVE-2024-30008
5.5 MEDIUM

Windows DWM Core Library Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30005
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30004
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30003
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30002
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30001
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30000
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29999
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29998
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29997
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-27108
6.8 MEDIUM

Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-27106
5.7 MEDIUM

Vulnerable data in transit in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-26007
5.3 MEDIUM

An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service …

May 14, 2024
CVE-2024-1629
6.2 MEDIUM

Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component

May 14, 2024
CVE-2023-50180
5.5 MEDIUM

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 …

May 14, 2024
CVE-2023-45586
5.0 MEDIUM

An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 …

May 14, 2024
CVE-2023-45583
6.7 MEDIUM

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 …

May 14, 2024
CVE-2023-44247
6.6 MEDIUM

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP …

May 14, 2024
CVE-2023-36640
6.7 MEDIUM

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, …

May 14, 2024
CVE-2023-24204
5.4 MEDIUM

SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

May 14, 2024
CVE-2023-24203
5.4 MEDIUM

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

May 14, 2024
CVE-2024-4871
6.8 MEDIUM

A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the …

May 14, 2024
CVE-2024-4860
5.4 MEDIUM

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the …

May 14, 2024
CVE-2024-4859
5.7 MEDIUM

Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.

May 14, 2024
CVE-2024-4624
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the …

May 14, 2024
CVE-2024-4473
6.4 MEDIUM

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.