CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30079
7.8 HIGH

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Jul 9, 2024
CVE-2024-30071
4.7 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

Jul 9, 2024
CVE-2024-30061
7.3 HIGH

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Jul 9, 2024
CVE-2024-30013
8.8 HIGH

Windows MultiPoint Services Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-28928
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-28899
8.8 HIGH

Secure Boot Security Feature Bypass Vulnerability

Jul 9, 2024
CVE-2024-26279
6.1 MEDIUM

The wrapper extensions do not correctly validate inputs, leading to XSS vectors.

Jul 9, 2024
CVE-2024-26278
6.1 MEDIUM

The Custom Fields component not correctly filter inputs, leading to a XSS vector.

Jul 9, 2024
CVE-2024-26184
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jul 9, 2024
CVE-2024-21731
6.1 MEDIUM

Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.

Jul 9, 2024
CVE-2024-21730
5.4 MEDIUM

The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.

Jul 9, 2024
CVE-2024-21729
6.1 MEDIUM

Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

Jul 9, 2024
CVE-2024-21449
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21428
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21425
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21415
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21414
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21398
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21373
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21335
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21333
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21332
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21331
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21317
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21308
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21303
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-20701
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-33509
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions and 6.3 all versions may allow a remote …

Jul 9, 2024
CVE-2024-27785
5.4 MEDIUM

An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenticated attacker to execute arbitrary …

Jul 9, 2024
CVE-2024-27784
8.8 HIGH

Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive …

Jul 9, 2024
CVE-2024-27783
7.6 HIGH

Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of …

Jul 9, 2024
CVE-2024-27782
8.1 HIGH

Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations …

Jul 9, 2024
CVE-2024-26015
3.4 LOW

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and …

Jul 9, 2024
CVE-2024-23663
8.8 HIGH

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows …

Jul 9, 2024
CVE-2024-21759
4.3 MEDIUM

An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or …

Jul 9, 2024
CVE-2023-50181
4.9 MEDIUM

An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some …

Jul 9, 2024
CVE-2023-50179
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote and unauthenticated attacker …

Jul 9, 2024
CVE-2023-50178
7.4 HIGH

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and …

Jul 9, 2024
CVE-2023-40702

PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication …

Jul 9, 2024
CVE-2023-40356

PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for …

Jul 9, 2024
CVE-2024-6615
8.8 HIGH

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Jul 9, 2024
CVE-2024-6614
4.3 MEDIUM

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 …

Jul 9, 2024
CVE-2024-6613
5.5 MEDIUM

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 …

Jul 9, 2024
CVE-2024-6612
5.3 MEDIUM

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that …

Jul 9, 2024
CVE-2024-6611
9.8 CRITICAL

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

Jul 9, 2024
CVE-2024-6610
4.3 MEDIUM

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability …

Jul 9, 2024
CVE-2024-6609
8.8 HIGH

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < …

Jul 9, 2024
CVE-2024-6608
4.3 MEDIUM

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. …

Jul 9, 2024
CVE-2024-6607
8.8 HIGH

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `&lt;select&gt;` element over certain permission …

Jul 9, 2024
CVE-2024-6606
8.2 HIGH

Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 …

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.