CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2207
6.0 MEDIUM

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of …

Nov 12, 2024
CVE-2024-51722
6.4 MEDIUM

A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained …

Nov 12, 2024
CVE-2024-47458
5.5 MEDIUM

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit …

Nov 12, 2024
CVE-2024-47457
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Nov 12, 2024
CVE-2024-47456
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47455
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47454
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47453
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47449
5.5 MEDIUM

Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 12, 2024
CVE-2024-47446
5.5 MEDIUM

After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47445
5.5 MEDIUM

After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47444
5.5 MEDIUM

After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-45147
5.5 MEDIUM

Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 12, 2024
CVE-2024-36509
4.2 MEDIUM

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, …

Nov 12, 2024
CVE-2024-33510
4.3 MEDIUM

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and …

Nov 12, 2024
CVE-2024-33505
5.6 MEDIUM

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, …

Nov 12, 2024
CVE-2024-32118
6.7 MEDIUM

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before …

Nov 12, 2024
CVE-2024-32117
4.9 MEDIUM

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer …

Nov 12, 2024
CVE-2024-32116
5.1 MEDIUM

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and …

Nov 12, 2024
CVE-2024-31496
6.7 MEDIUM

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and …

Nov 12, 2024
CVE-2024-26011
5.3 MEDIUM

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, …

Nov 12, 2024
CVE-2023-47543
5.4 MEDIUM

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other …

Nov 12, 2024
CVE-2023-44255
4.1 MEDIUM

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a …

Nov 12, 2024
CVE-2024-51720
4.8 MEDIUM

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll …

Nov 12, 2024
CVE-2024-49044
6.7 MEDIUM

Visual Studio Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43646
6.7 MEDIUM

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43645
6.7 MEDIUM

Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

Nov 12, 2024
CVE-2024-43643
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43638
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43637
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43634
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43633
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Nov 12, 2024
CVE-2024-43631
6.7 MEDIUM

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43451
6.5 MEDIUM KEV

NTLM Hash Disclosure Spoofing Vulnerability

Nov 12, 2024
CVE-2024-43449
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-38264
5.9 MEDIUM

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

Nov 12, 2024
CVE-2024-38203
6.2 MEDIUM

Windows Package Library Manager Information Disclosure Vulnerability

Nov 12, 2024
CVE-2024-21949
5.5 MEDIUM

Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.

Nov 12, 2024
CVE-2024-9999
6.5 MEDIUM

In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification …

Nov 12, 2024
CVE-2024-9843
5.0 MEDIUM

A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.

Nov 12, 2024
CVE-2024-51750
5.0 MEDIUM

Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element …

Nov 12, 2024
CVE-2024-49527
5.5 MEDIUM

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 12, 2024
CVE-2024-30133
5.3 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating …

Nov 12, 2024
CVE-2024-11004
6.1 MEDIUM

Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. …

Nov 12, 2024
CVE-2024-52296
6.5 MEDIUM

libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. At …

Nov 12, 2024
CVE-2024-47909
4.9 MEDIUM

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin …

Nov 12, 2024
CVE-2024-47905
4.9 MEDIUM

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin …

Nov 12, 2024
CVE-2024-47535
5.5 MEDIUM

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file …

Nov 12, 2024
CVE-2024-10971
4.3 MEDIUM

Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty …

Nov 12, 2024
CVE-2024-51566
6.5 MEDIUM

The NVMe driver queue processing is vulernable to guest-induced infinite loops.

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.