CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4367
8.8 HIGH

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-27110
8.4 HIGH

Elevation of privilege vulnerability in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-31491
8.8 HIGH

A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands …

May 14, 2024
CVE-2024-30051
7.8 HIGH KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30049
7.8 HIGH

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30048
7.6 HIGH

Dynamics 365 Customer Insights Spoofing Vulnerability

May 14, 2024
CVE-2024-30047
7.6 HIGH

Dynamics 365 Customer Insights Spoofing Vulnerability

May 14, 2024
CVE-2024-30044
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30042
7.8 HIGH

Microsoft Excel Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30040
8.8 HIGH KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

May 14, 2024
CVE-2024-30038
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30035
7.8 HIGH

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30033
7.0 HIGH

Windows Search Service Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30032
7.8 HIGH

Windows DWM Core Library Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30031
7.8 HIGH

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30030
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30029
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30028
7.8 HIGH

Win32k Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30027
7.8 HIGH

NTFS Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30025
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30024
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30023
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30022
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30020
8.1 HIGH

Windows Cryptographic Services Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30018
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30017
8.8 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30015
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30014
7.5 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30010
8.8 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30009
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-30007
8.8 HIGH

Microsoft Brokering File System Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-30006
8.8 HIGH

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

May 14, 2024
CVE-2024-29996
7.8 HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-29994
7.8 HIGH

Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-27109
7.6 HIGH

Insufficiently protected credentials in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-26238
7.8 HIGH

Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability

May 14, 2024
CVE-2024-23105
7.5 HIGH

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to …

May 14, 2024
CVE-2024-1630
7.7 HIGH

Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component

May 14, 2024
CVE-2023-46714
7.2 HIGH

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative …

May 14, 2024
CVE-2023-40720
7.1 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP …

May 14, 2024
CVE-2024-4761
8.8 HIGH KEV

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via …

May 14, 2024
CVE-2024-3372
7.5 HIGH

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application …

May 14, 2024
CVE-2024-35010
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6.

May 14, 2024
CVE-2024-35009
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=&fieldName=state&fieldName2=state&tabName=banner&dataID=6.

May 14, 2024
CVE-2024-34950
7.5 HIGH

D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.

May 14, 2024
CVE-2024-34773
7.8 HIGH

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected applications contain a stack overflow vulnerability while parsing specially …

May 14, 2024
CVE-2024-34772
7.8 HIGH

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 4). The affected applications contain an out of bounds read past the …

May 14, 2024
CVE-2024-34771
7.8 HIGH

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing …

May 14, 2024
CVE-2024-34714
7.6 HIGH

The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made …

May 14, 2024
CVE-2024-34086
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.