Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2024-4347 | The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or other sites in a shared hosting environment. | Unknown | N/A | emrevona | |
CVE-2024-43470 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43472 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43474 | Microsoft SQL Server Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43475 | Microsoft Windows Admin Center Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43476 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43477 | Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. | Unknown | N/A | Microsoft | |
CVE-2024-43479 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4348 | A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262488. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | Unknown | N/A | n/a | |
CVE-2024-43480 | Azure Service Fabric for Linux Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43481 | Power BI Report Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43482 | Microsoft Outlook for iOS Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43483 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43484 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43485 | .NET and Visual Studio Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43487 | Windows Mark of the Web Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43488 | Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. | Unknown | N/A | Microsoft | |
CVE-2024-43489 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4349 | A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262489 was assigned to this vulnerability. | Unknown | N/A | SourceCodester | |
CVE-2024-43491 | Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support. | Unknown | N/A | Microsoft | |
CVE-2024-43492 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43495 | Windows libarchive Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43496 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43497 | DeepSpeed Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4350 | Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject malicious code into fields due to insufficient input validation. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.0 with a vector of AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator and a CVSS v4 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Thanks, m3dium for reporting. | Unknown | N/A | Concrete CMS | |
CVE-2024-43500 | Windows Resilient File System (ReFS) Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43501 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43502 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43503 | Microsoft SharePoint Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43504 | Microsoft Excel Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43505 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43506 | BranchCache Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43508 | Windows Graphics Component Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43509 | Windows Graphics Component Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4351 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account. | Unknown | N/A | themium | |
CVE-2024-43511 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43512 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43513 | BitLocker Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43514 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43515 | Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43516 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43517 | Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43518 | Windows Telephony Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43519 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4352 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the ‘year’ parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | Unknown | N/A | themium | |
CVE-2024-43520 | Windows Kernel Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43521 | Windows Hyper-V Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43522 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43523 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43524 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43525 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43526 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43527 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43528 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43529 | Windows Print Spooler Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4353 | Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board instance functionality. The Name input field does not check the input sufficiently letting a rogue administrator have the capability to inject malicious JavaScript code. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 3.1 with a vector of AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator and a CVSS v4 score of 1.8 with a vector of CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Concrete versions below 9 are not affected by this vulnerability. Thanks fhAnso for reporting. | Unknown | N/A | Concrete CMS | |
CVE-2024-43532 | Remote Registry Service Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43533 | Remote Desktop Client Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43534 | Windows Graphics Component Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43535 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43536 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43537 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43538 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4354 | The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Due to the complex nature of protecting against DNS rebind attacks in WordPress software, we settled on the developer simply restricting the usage of the URL import functionality to just administrators. While this is not optimal, we feel this poses a minimal risk to most site owners and ideally WordPress core would correct this issue in wp_safe_remote_get() and other functions. | Unknown | N/A | tobiasbg | |
CVE-2024-43540 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43541 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43542 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43543 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43544 | Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43545 | Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43546 | Windows Cryptographic Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43547 | Windows Kerberos Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43549 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4355 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the stopbadbots_get_ajax_data() function in all versions up to, and including, 10.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose visitor data. | Unknown | N/A | sminozzi | |
CVE-2024-43550 | Windows Secure Channel Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43551 | Windows Storage Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43552 | Windows Shell Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43553 | NT OS Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43554 | Windows Kernel-Mode Driver Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43555 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43556 | Windows Graphics Component Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43557 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43558 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43559 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4356 | The List categories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'categories' shortcode in all versions up to, and including, 0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | Unknown | N/A | fernandobt | |
CVE-2024-43560 | Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43561 | Windows Mobile Broadband Driver Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43562 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43563 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43564 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43565 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43566 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43567 | Windows Hyper-V Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-4357 | An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing. | Unknown | N/A | Progress Software | |
CVE-2024-43570 | Windows Kernel Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43571 | Sudo for Windows Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43572 | Microsoft Management Console Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43573 | Windows MSHTML Platform Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43574 | Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2024-43575 | Windows Hyper-V Denial of Service Vulnerability | Unknown | N/A | Microsoft |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v