CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2637
7.2 HIGH

An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation …

May 14, 2024
CVE-2024-4777
8.8 HIGH

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume …

May 14, 2024
CVE-2024-4776
8.2 HIGH

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4773
7.5 HIGH

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been …

May 14, 2024
CVE-2024-4771
8.6 HIGH

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be …

May 14, 2024
CVE-2024-4770
8.8 HIGH

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR …

May 14, 2024
CVE-2024-4765
8.1 HIGH

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have …

May 14, 2024
CVE-2024-4367
8.8 HIGH

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-27110
8.4 HIGH

Elevation of privilege vulnerability in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-31491
8.8 HIGH

A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands …

May 14, 2024
CVE-2024-30051
7.8 HIGH KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30049
7.8 HIGH

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30048
7.6 HIGH

Dynamics 365 Customer Insights Spoofing Vulnerability

May 14, 2024
CVE-2024-30047
7.6 HIGH

Dynamics 365 Customer Insights Spoofing Vulnerability

May 14, 2024
CVE-2024-30044
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30042
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30040
8.8 HIGH KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

May 14, 2024
CVE-2024-30038
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30035
7.8 HIGH

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30033
7.0 HIGH

Windows Search Service Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30032
7.8 HIGH

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30031
7.8 HIGH

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30030
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30029
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30028
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30027
7.8 HIGH

NTFS Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30025
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30024
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30023
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30022
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30020
8.1 HIGH

Windows Cryptographic Services Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30018
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30017
8.8 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30015
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30014
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30010
8.8 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30009
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30007
8.8 HIGH

Microsoft Brokering File System Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30006
8.8 HIGH

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29996
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-29994
7.8 HIGH

Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-27109
7.6 HIGH

Insufficiently protected credentials in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-26238
7.8 HIGH

Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-23105
7.5 HIGH

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to …

May 14, 2024
CVE-2024-1630
7.7 HIGH

Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component

May 14, 2024
CVE-2023-46714
7.2 HIGH

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative …

May 14, 2024
CVE-2023-40720
7.1 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP …

May 14, 2024
CVE-2024-4761
8.8 HIGH KEV

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via …

May 14, 2024
CVE-2024-3372
7.5 HIGH

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application …

May 14, 2024
CVE-2024-35010
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.