CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-38054

    Last Modified: 10 Feb 2026

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-38051

    Last Modified: 10 Feb 2026

    Windows Graphics Component Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-38043

    Last Modified: 10 Feb 2026

    PowerShell Elevation of Privilege Vulnerability

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-38041

    Last Modified: 10 Feb 2026

    Windows Kernel Information Disclosure Vulnerability

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-38034

    Last Modified: 10 Feb 2026

    Windows Filtering Platform Elevation of Privilege Vulnerability

    Published: 9 Jul 2024
    7.2
    High

    CVE-2024-38025

    Last Modified: 10 Feb 2026

    Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    7.2
    High

    CVE-2024-38024

    Last Modified: 10 Feb 2026

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    7.2
    High

    CVE-2024-38023

    Last Modified: 10 Feb 2026

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    7
    High

    CVE-2024-38022

    Last Modified: 10 Feb 2026

    Windows Image Acquisition Elevation of Privilege Vulnerability

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-38015

    Last Modified: 10 Feb 2026

    Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

    Published: 9 Jul 2024
    6.7
    Medium

    CVE-2024-38013

    Last Modified: 10 Feb 2026

    Microsoft Windows Server Backup Elevation of Privilege Vulnerability

    Published: 9 Jul 2024
    8
    High

    CVE-2024-37987

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    8
    High

    CVE-2024-37986

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    8
    High

    CVE-2024-37981

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    8
    High

    CVE-2024-37974

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    8
    High

    CVE-2024-37970

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    8
    High

    CVE-2024-37969

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-37331

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-37332

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-37318

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21428

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21415

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21414

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21398

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21373

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21335

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21333

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-21332

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-38087

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-38088

    Last Modified: 9 Dec 2025

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-35270

    Last Modified: 10 Feb 2026

    Windows iSCSI Service Denial of Service Vulnerability

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-30098

    Last Modified: 10 Feb 2026

    Windows Cryptographic Services Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    7.1
    High

    CVE-2024-30081

    Last Modified: 10 Feb 2026

    Windows NTLM Spoofing Vulnerability

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-28899

    Last Modified: 10 Feb 2026

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Jul 2024
    7.3
    High

    CVE-2024-30061

    Last Modified: 9 Dec 2025

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-21729

    Last Modified: 26 Mar 2025

    Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

    Published: 9 Jul 2024
    5.4
    Medium

    CVE-2024-21730

    Last Modified: 20 Mar 2025

    The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-26279

    Last Modified: 26 Mar 2025

    The wrapper extensions do not correctly validate inputs, leading to XSS vectors.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-26278

    Last Modified: 14 Mar 2025

    The Custom Fields component not correctly filter inputs, leading to a XSS vector.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-21731

    Last Modified: 14 Mar 2025

    Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.

    Published: 9 Jul 2024
    6.5
    Medium

    CVE-2024-6237

    Last Modified: 20 Nov 2025

    A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.

    Published: 9 Jul 2024
    8.7
    High

    CVE-2023-40356

    Last Modified: 15 Apr 2026

    PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered devices. A threat actor might be able to exploit this vulnerability to register their own MFA device with a target user’s account if they have existing knowledge of the target user’s first factor credential.

    Published: 9 Jul 2024
    7.7
    High

    CVE-2023-40702

    Last Modified: 15 Apr 2026

    PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication from the user's existing registered devices. A threat actor might be able to exploit this vulnerability to authenticate as a target user if they have existing knowledge of the target user’s first-factor credentials.

    Published: 9 Jul 2024
    7.4
    High

    CVE-2023-50178

    Last Modified: 21 Nov 2024

    An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and various remote servers such as private SDN connectors and FortiToken Cloud.

    Published: 9 Jul 2024
    4.9
    Medium

    CVE-2023-50181

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-23663

    Last Modified: 21 Nov 2024

    An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.

    Published: 9 Jul 2024
    4.3
    Medium

    CVE-2024-21759

    Last Modified: 21 Nov 2024

    An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2024-27782

    Last Modified: 9 Jan 2026

    Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.

    Published: 9 Jul 2024
    3.4
    Low

    CVE-2024-26015

    Last Modified: 21 Nov 2024

    An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-27784

    Last Modified: 9 Jan 2026

    Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files.

    Published: 9 Jul 2024