CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37319
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-37318
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-35272
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-35271
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-35267
7.6 HIGH

Azure DevOps Server Spoofing Vulnerability

Jul 9, 2024
CVE-2024-35266
7.6 HIGH

Azure DevOps Server Spoofing Vulnerability

Jul 9, 2024
CVE-2024-35264
8.1 HIGH

.NET and Visual Studio Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-35261
7.8 HIGH

Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

Jul 9, 2024
CVE-2024-35256
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-32987
7.5 HIGH

Microsoft SharePoint Server Information Disclosure Vulnerability

Jul 9, 2024
CVE-2024-30105
7.5 HIGH

.NET and Visual Studio Denial of Service Vulnerability

Jul 9, 2024
CVE-2024-30098
7.5 HIGH

Windows Cryptographic Services Security Feature Bypass Vulnerability

Jul 9, 2024
CVE-2024-30081
7.1 HIGH

Windows NTLM Spoofing Vulnerability

Jul 9, 2024
CVE-2024-30079
7.8 HIGH

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Jul 9, 2024
CVE-2024-30061
7.3 HIGH

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Jul 9, 2024
CVE-2024-30013
8.8 HIGH

Windows MultiPoint Services Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-28928
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-28899
8.8 HIGH

Secure Boot Security Feature Bypass Vulnerability

Jul 9, 2024
CVE-2024-21449
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21428
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21425
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21415
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21414
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21398
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21373
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21335
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21333
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21332
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21331
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21317
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21308
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-21303
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-20701
8.8 HIGH

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-27784
8.8 HIGH

Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive …

Jul 9, 2024
CVE-2024-27783
7.6 HIGH

Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of …

Jul 9, 2024
CVE-2024-27782
8.1 HIGH

Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations …

Jul 9, 2024
CVE-2024-23663
8.8 HIGH

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows …

Jul 9, 2024
CVE-2023-50178
7.4 HIGH

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and …

Jul 9, 2024
CVE-2024-6615
8.8 HIGH

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Jul 9, 2024
CVE-2024-6609
8.8 HIGH

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < …

Jul 9, 2024
CVE-2024-6607
8.8 HIGH

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `&lt;select&gt;` element over certain permission …

Jul 9, 2024
CVE-2024-6606
8.2 HIGH

Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 …

Jul 9, 2024
CVE-2024-6605
8.8 HIGH

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

Jul 9, 2024
CVE-2024-6604
7.5 HIGH

Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume …

Jul 9, 2024
CVE-2024-6603
7.4 HIGH

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects …

Jul 9, 2024
CVE-2024-39697
8.6 HIGH

phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds …

Jul 9, 2024
CVE-2024-38363
8.5 HIGH

Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE via SSTI which allows an authenticated remote …

Jul 9, 2024
CVE-2024-37952
8.8 HIGH

Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects BookYourTravel: from n/a through 8.18.17.

Jul 9, 2024
CVE-2024-37513
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue affects WPCafe: from n/a through 2.2.27.

Jul 9, 2024
CVE-2024-22271
8.2 HIGH

In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to …

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.