CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30004
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30003
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30002
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30001
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30000
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29999
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29998
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29997
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29996
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-29994
7.8 HIGH

Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-27109
7.6 HIGH

Insufficiently protected credentials in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-27108
6.8 MEDIUM

Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-27107
9.6 CRITICAL

Weak account password in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-27106
5.7 MEDIUM

Vulnerable data in transit in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-26238
7.8 HIGH

Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-26007
5.3 MEDIUM

An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service …

May 14, 2024
CVE-2024-23105
7.5 HIGH

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to …

May 14, 2024
CVE-2024-1630
7.7 HIGH

Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component

May 14, 2024
CVE-2024-1629
6.2 MEDIUM

Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component

May 14, 2024
CVE-2023-50180
5.5 MEDIUM

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 …

May 14, 2024
CVE-2023-46714
7.2 HIGH

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative …

May 14, 2024
CVE-2023-45586
5.0 MEDIUM

An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 …

May 14, 2024
CVE-2023-45583
6.7 MEDIUM

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 …

May 14, 2024
CVE-2023-44247
6.6 MEDIUM

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP …

May 14, 2024
CVE-2023-40720
7.1 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP …

May 14, 2024
CVE-2023-36640
6.7 MEDIUM

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, …

May 14, 2024
CVE-2023-24204
5.4 MEDIUM

SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

May 14, 2024
CVE-2023-24203
5.4 MEDIUM

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

May 14, 2024
CVE-2024-4871
6.8 MEDIUM

A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the …

May 14, 2024
CVE-2024-4860
5.4 MEDIUM

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the …

May 14, 2024
CVE-2024-4859
5.7 MEDIUM

Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.

May 14, 2024
CVE-2024-4810

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE has been replaced by CVE-2024-36015.

May 14, 2024
CVE-2024-4761
8.8 HIGH KEV

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via …

May 14, 2024
CVE-2024-4624
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the …

May 14, 2024
CVE-2024-4473
6.4 MEDIUM

The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 …

May 14, 2024
CVE-2024-4445
6.5 MEDIUM

The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

May 14, 2024
CVE-2024-4440
6.4 MEDIUM

The 140+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all …

May 14, 2024
CVE-2024-4392
6.4 MEDIUM

The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all …

May 14, 2024
CVE-2024-4333
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

May 14, 2024
CVE-2024-4144
6.5 MEDIUM

The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This …

May 14, 2024
CVE-2024-4139
4.3 MEDIUM

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an …

May 14, 2024
CVE-2024-4138
4.3 MEDIUM

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an …

May 14, 2024
CVE-2024-3579
6.1 MEDIUM

Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will …

May 14, 2024
CVE-2024-3374
5.3 MEDIUM

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that …

May 14, 2024
CVE-2024-3372
7.5 HIGH

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application …

May 14, 2024
CVE-2024-3241
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where …

May 14, 2024
CVE-2024-35012
6.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&nohrefStr=close.

May 14, 2024
CVE-2024-35011
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&nohrefStr=close.

May 14, 2024
CVE-2024-35010
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6.

May 14, 2024
CVE-2024-35009
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=&fieldName=state&fieldName2=state&tabName=banner&dataID=6.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.