Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2024-3814 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | tagDiv | |
CVE-2024-38140 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38141 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38142 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38143 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38144 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38145 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38146 | Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38147 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38148 | Windows Secure Channel Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38149 | BranchCache Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3815 | The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | n/a | |
CVE-2024-38150 | Windows DWM Core Library Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38151 | Windows Kernel Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38152 | Windows OLE Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38153 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38154 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38155 | Security Center Broker Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38156 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38157 | Azure IoT SDK Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38158 | Azure IoT SDK Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38159 | Windows Network Virtualization Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3816 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears. | Unknown | N/A | Concept Intermedia | |
CVE-2024-38160 | Windows Network Virtualization Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38161 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38162 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38163 | Windows Update Stack Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38164 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | Unknown | N/A | Microsoft | |
CVE-2024-38165 | Windows Compressed Folder Tampering Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38166 | An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. | Unknown | N/A | Microsoft | |
CVE-2024-38167 | .NET and Visual Studio Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38168 | .NET and Visual Studio Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38169 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3817 | HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. | Unknown | N/A | HashiCorp | |
CVE-2024-38170 | Microsoft Excel Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38171 | Microsoft PowerPoint Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38172 | Microsoft Excel Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38173 | Microsoft Outlook Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38175 | An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. | Unknown | N/A | Microsoft | |
CVE-2024-38176 | An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | Unknown | N/A | Microsoft | |
CVE-2024-38177 | Windows App Installer Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38178 | Scripting Engine Memory Corruption Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38179 | Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3818 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | wpdevteam | |
CVE-2024-38180 | Windows SmartScreen Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38182 | Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | Unknown | N/A | Microsoft | |
CVE-2024-38183 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | Unknown | N/A | Microsoft | |
CVE-2024-38184 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38185 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38186 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38187 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38188 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38189 | Microsoft Project Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3819 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Banner widget in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | jegtheme | |
CVE-2024-38190 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | Unknown | N/A | Microsoft | |
CVE-2024-38191 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38193 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38194 | An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | Unknown | N/A | Microsoft | |
CVE-2024-38195 | Azure CycleCloud Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38196 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38197 | Microsoft Teams for iOS Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38198 | Windows Print Spooler Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38199 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3820 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Please note this only affects the premium version of the plugin. | Unknown | N/A | wpdatatables | |
CVE-2024-38200 | Microsoft Office Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38201 | Azure Stack Hub Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38202 | Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacker attempting to exploit this vulnerability requires additional interaction by a privileged user to be successful. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. **Note:**Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this vulnerability and to protect their systems. If there are any further updates regarding mitigations for this vulnerability, this CVE will be updated and customers will be notified. We highly encourage customers to subscribe to Security Update Guide notifications to receive an alert if an update occurs. Details A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows Update potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of VBS. For exploitation to succeed, an attacker must trick or convince an Administrator or a user with delegated permissions into performing a system restore which inadvertently triggers the vulnerability. Microsoft has developed a security update to mitigate this threat which was made available October 08, 2024 and is provided in the Security Updates table of this CVE for customers to download. **Note:**Depending on your version of Windows, additional steps may be required to update Windows Recovery Environment (WinRE) to be protected from this vulnerability. Please refer to the FAQ section for more information. Guidance for customers who cannot immediately implement the update is provided in the Recommended Actions section of this CVE to help reduce the risks associated with this vulnerability and to protect their systems. If there are any... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38202 | Unknown | N/A | Microsoft | |
CVE-2024-38204 | Improper Access Control in Imagine Cup allows an authorized attacker to elevate privileges over a network. | Unknown | N/A | Microsoft | |
CVE-2024-38206 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | Unknown | N/A | Microsoft | |
CVE-2024-38207 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38208 | Microsoft Edge for Android Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38209 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3821 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the wdt_ajax_actions.php file in all versions up to, and including, 6.3.2. This makes it possible for unauthenticated attackers to manipulate data tables. Please note this only affects the premium version of the plugin. | Unknown | N/A | wpdatatables | |
CVE-2024-38210 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38211 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38212 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38213 | Windows Mark of the Web Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38214 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38215 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38216 | Azure Stack Hub Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38217 | Windows Mark of the Web Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38218 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38219 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3822 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | Unknown | N/A | Unknown | |
CVE-2024-38220 | Azure Stack Hub Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38221 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38222 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38223 | Windows Initial Machine Configuration Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38225 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38226 | Microsoft Publisher Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38227 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38228 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38229 | .NET and Visual Studio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-3823 | The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | Unknown | N/A | Unknown | |
CVE-2024-38230 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38231 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38232 | Windows Networking Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38233 | Windows Networking Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38234 | Windows Networking Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-38235 | Windows Hyper-V Denial of Service Vulnerability | Unknown | N/A | Microsoft |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v