CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36513
8.2 HIGH

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated …

Nov 12, 2024
CVE-2024-36509
4.2 MEDIUM

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, …

Nov 12, 2024
CVE-2024-36507
7.3 HIGH

A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via …

Nov 12, 2024
CVE-2024-35274
2.3 LOW

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 …

Nov 12, 2024
CVE-2024-33510
4.3 MEDIUM

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and …

Nov 12, 2024
CVE-2024-33505
5.6 MEDIUM

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, …

Nov 12, 2024
CVE-2024-32118
6.7 MEDIUM

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before …

Nov 12, 2024
CVE-2024-32117
4.9 MEDIUM

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer …

Nov 12, 2024
CVE-2024-32116
5.1 MEDIUM

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and …

Nov 12, 2024
CVE-2024-31496
6.7 MEDIUM

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and …

Nov 12, 2024
CVE-2024-26011
5.3 MEDIUM

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, …

Nov 12, 2024
CVE-2024-23666
7.5 HIGH

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 …

Nov 12, 2024
CVE-2023-52268
9.1 CRITICAL

The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent …

Nov 12, 2024
CVE-2023-50176
7.5 HIGH

A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or …

Nov 12, 2024
CVE-2023-47543
5.4 MEDIUM

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other …

Nov 12, 2024
CVE-2023-44255
4.1 MEDIUM

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a …

Nov 12, 2024
CVE-2024-8069
8.0 HIGH KEV

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same …

Nov 12, 2024
CVE-2024-8068
8.0 HIGH KEV

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as …

Nov 12, 2024
CVE-2024-51720
4.8 MEDIUM

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll …

Nov 12, 2024
CVE-2024-49056
7.3 HIGH

Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.

Nov 12, 2024
CVE-2024-49051
7.8 HIGH

Microsoft PC Manager Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-49050
8.8 HIGH

Visual Studio Code Python Extension Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49049
7.1 HIGH

Visual Studio Code Remote Extension Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-49048
8.1 HIGH

TorchGeo Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49046
7.8 HIGH

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-49044
6.7 MEDIUM

Visual Studio Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-49043
7.8 HIGH

Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49040
7.5 HIGH

Microsoft Exchange Server Spoofing Vulnerability

Nov 12, 2024
CVE-2024-49039
8.8 HIGH KEV

Windows Task Scheduler Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-49033
7.5 HIGH

Microsoft Word Security Feature Bypass Vulnerability

Nov 12, 2024
CVE-2024-49032
7.8 HIGH

Microsoft Office Graphics Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49031
7.8 HIGH

Microsoft Office Graphics Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49030
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49029
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49028
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49027
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49026
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49021
7.8 HIGH

Microsoft SQL Server Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49019
7.8 HIGH

Active Directory Certificate Services Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-49018
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49017
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49016
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49015
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49014
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49013
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49012
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49011
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49010
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49009
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024
CVE-2024-49008
8.8 HIGH

SQL Server Native Client Remote Code Execution Vulnerability

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.