CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-28132
7.2 HIGH

The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers …

May 14, 2024
CVE-2020-26312
8.1 HIGH

Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in …

May 14, 2024
CVE-2024-32465
7.3 HIGH

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone …

May 14, 2024
CVE-2024-32021
3.9 LOW

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains …

May 14, 2024
CVE-2021-22280
7.2 HIGH

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of …

May 14, 2024
CVE-2024-3676
7.5 HIGH

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP …

May 14, 2024
CVE-2024-32020
3.9 LOW

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into …

May 14, 2024
CVE-2024-32004
8.1 HIGH

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in …

May 14, 2024
CVE-2024-32002
9.0 CRITICAL

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a …

May 14, 2024
CVE-2024-2637
7.2 HIGH

An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation …

May 14, 2024
CVE-2024-0862
5.0 MEDIUM

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the …

May 14, 2024
CVE-2024-4778
9.8 CRITICAL

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

May 14, 2024
CVE-2024-4777
8.8 HIGH

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume …

May 14, 2024
CVE-2024-4776
8.2 HIGH

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4775
5.9 MEDIUM

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This …

May 14, 2024
CVE-2024-4774
6.5 MEDIUM

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-4773
7.5 HIGH

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been …

May 14, 2024
CVE-2024-4772
5.9 MEDIUM

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4771
8.6 HIGH

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be …

May 14, 2024
CVE-2024-4770
8.8 HIGH

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR …

May 14, 2024
CVE-2024-4769
5.9 MEDIUM

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn …

May 14, 2024
CVE-2024-4768
6.1 MEDIUM

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox …

May 14, 2024
CVE-2024-4767
4.3 MEDIUM

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. …

May 14, 2024
CVE-2024-4766
4.3 MEDIUM

Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug …

May 14, 2024
CVE-2024-4765
8.1 HIGH

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have …

May 14, 2024
CVE-2024-4764
9.8 CRITICAL

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4367
8.8 HIGH

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-33485
9.8 CRITICAL

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted …

May 14, 2024
CVE-2024-27110
8.4 HIGH

Elevation of privilege vulnerability in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-31491
8.8 HIGH

A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands …

May 14, 2024
CVE-2024-31488
6.8 MEDIUM

An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through …

May 14, 2024
CVE-2024-30059
6.1 MEDIUM

Microsoft Intune for Android Mobile Application Management Tampering Vulnerability

May 14, 2024
CVE-2024-30054
6.5 MEDIUM

Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30053
6.5 MEDIUM

Azure Migrate Cross-Site Scripting Vulnerability

May 14, 2024
CVE-2024-30051
7.8 HIGH KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30050
5.4 MEDIUM

Windows Mark of the Web Security Feature Bypass Vulnerability

May 14, 2024
CVE-2024-30049
7.8 HIGH

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30048
7.6 HIGH

Dynamics 365 Customer Insights Spoofing Vulnerability

May 14, 2024
CVE-2024-30047
7.6 HIGH

Dynamics 365 Customer Insights Spoofing Vulnerability

May 14, 2024
CVE-2024-30046
5.9 MEDIUM

Visual Studio Denial of Service Vulnerability

May 14, 2024
CVE-2024-30045
6.3 MEDIUM

.NET and Visual Studio Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30044
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30043
6.5 MEDIUM

Microsoft SharePoint Server Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30042
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30041
5.4 MEDIUM

Microsoft Bing Search Spoofing Vulnerability

May 14, 2024
CVE-2024-30040
8.8 HIGH KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

May 14, 2024
CVE-2024-30039
5.5 MEDIUM

Windows Remote Access Connection Manager Information Disclosure Vulnerability

May 14, 2024
CVE-2024-30038
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30037
5.5 MEDIUM

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30036
6.5 MEDIUM

Windows Deployment Services Information Disclosure Vulnerability

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.