CVE-2024-38054
Last Modified: 10 Feb 2026Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2024-38051
Last Modified: 10 Feb 2026Windows Graphics Component Remote Code Execution Vulnerability
CVE-2024-38043
Last Modified: 10 Feb 2026PowerShell Elevation of Privilege Vulnerability
CVE-2024-38041
Last Modified: 10 Feb 2026Windows Kernel Information Disclosure Vulnerability
CVE-2024-38034
Last Modified: 10 Feb 2026Windows Filtering Platform Elevation of Privilege Vulnerability
CVE-2024-38025
Last Modified: 10 Feb 2026Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
CVE-2024-38024
Last Modified: 10 Feb 2026Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-38023
Last Modified: 10 Feb 2026Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-38022
Last Modified: 10 Feb 2026Windows Image Acquisition Elevation of Privilege Vulnerability
CVE-2024-38015
Last Modified: 10 Feb 2026Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2024-38013
Last Modified: 10 Feb 2026Microsoft Windows Server Backup Elevation of Privilege Vulnerability
CVE-2024-37987
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37986
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37981
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37974
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37970
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37969
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-37331
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37332
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-37318
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21428
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21415
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21414
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21398
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21373
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21335
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21333
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21332
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-38087
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-38088
Last Modified: 9 Dec 2025SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-35270
Last Modified: 10 Feb 2026Windows iSCSI Service Denial of Service Vulnerability
CVE-2024-30098
Last Modified: 10 Feb 2026Windows Cryptographic Services Security Feature Bypass Vulnerability
CVE-2024-30081
Last Modified: 10 Feb 2026Windows NTLM Spoofing Vulnerability
CVE-2024-28899
Last Modified: 10 Feb 2026Secure Boot Security Feature Bypass Vulnerability
CVE-2024-30061
Last Modified: 9 Dec 2025Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-21729
Last Modified: 26 Mar 2025Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
CVE-2024-21730
Last Modified: 20 Mar 2025The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
CVE-2024-26279
Last Modified: 26 Mar 2025The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
CVE-2024-26278
Last Modified: 14 Mar 2025The Custom Fields component not correctly filter inputs, leading to a XSS vector.
CVE-2024-21731
Last Modified: 14 Mar 2025Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
CVE-2024-6237
Last Modified: 20 Nov 2025A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
CVE-2023-40356
Last Modified: 15 Apr 2026PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered devices. A threat actor might be able to exploit this vulnerability to register their own MFA device with a target user’s account if they have existing knowledge of the target user’s first factor credential.
CVE-2023-40702
Last Modified: 15 Apr 2026PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication from the user's existing registered devices. A threat actor might be able to exploit this vulnerability to authenticate as a target user if they have existing knowledge of the target user’s first-factor credentials.
CVE-2023-50178
Last Modified: 21 Nov 2024An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and various remote servers such as private SDN connectors and FortiToken Cloud.
CVE-2023-50181
Last Modified: 21 Nov 2024An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.
CVE-2024-23663
Last Modified: 21 Nov 2024An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
CVE-2024-21759
Last Modified: 21 Nov 2024An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests.
CVE-2024-27782
Last Modified: 9 Jan 2026Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests.
CVE-2024-26015
Last Modified: 21 Nov 2024An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.15 and below IP address validation feature may permit an unauthenticated attacker to bypass the IP blocklist via crafted requests.
CVE-2024-27784
Last Modified: 9 Jan 2026Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files.
