CVE-2024-30089
Last Modified: 17 Dec 2025Microsoft Streaming Service Elevation of Privilege Vulnerability
CVE-2024-30088
Last Modified: 17 Dec 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30087
Last Modified: 20 Jul 2026Win32k Elevation of Privilege Vulnerability
CVE-2024-30086
Last Modified: 17 Dec 2025Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2024-30085
Last Modified: 17 Dec 2025Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2024-30084
Last Modified: 20 Jul 2026Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-30083
Last Modified: 17 Dec 2025Windows Standards-Based Storage Management Service Denial of Service Vulnerability
CVE-2024-30068
Last Modified: 17 Dec 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30067
Last Modified: 17 Dec 2025Winlogon Elevation of Privilege Vulnerability
CVE-2024-30066
Last Modified: 17 Dec 2025Winlogon Elevation of Privilege Vulnerability
CVE-2024-30065
Last Modified: 17 Dec 2025Windows Themes Denial of Service Vulnerability
CVE-2024-30064
Last Modified: 17 Dec 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-30063
Last Modified: 20 Jul 2026Windows Distributed File System (DFS) Remote Code Execution Vulnerability
CVE-2024-30062
Last Modified: 17 Dec 2025Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability
CVE-2024-29060
Last Modified: 17 Dec 2025Visual Studio Elevation of Privilege Vulnerability
CVE-2024-35255
Last Modified: 17 Dec 2025Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-35250
Last Modified: 20 Jul 2026Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-30082
Last Modified: 20 Jul 2026Win32k Elevation of Privilege Vulnerability
CVE-2024-30080
Last Modified: 20 Jul 2026Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-30078
Last Modified: 20 Jul 2026Windows Wi-Fi Driver Remote Code Execution Vulnerability
CVE-2024-30077
Last Modified: 20 Jul 2026Windows OLE Remote Code Execution Vulnerability
CVE-2024-30076
Last Modified: 17 Dec 2025Windows Container Manager Service Elevation of Privilege Vulnerability
CVE-2024-30075
Last Modified: 20 Jul 2026Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
CVE-2024-30074
Last Modified: 20 Jul 2026Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
CVE-2024-30072
Last Modified: 17 Dec 2025Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability
CVE-2024-30070
Last Modified: 17 Dec 2025DHCP Server Service Denial of Service Vulnerability
CVE-2024-30069
Last Modified: 17 Dec 2025Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-34763
Last Modified: 28 Apr 2026Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from n/a through <= 1.01.5.
CVE-2024-37293
Last Modified: 21 Nov 2024The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined in AWS Organizations while taking advantage of services such as AWS CodePipeline, AWS CodeBuild, and AWS CodeCommit to alleviate the heavy lifting and management compared to a traditional CI/CD setup. ADF contains a bootstrap process that is responsible to deploy ADF's bootstrap stacks to facilitate multi-account cross-region deployments. The ADF bootstrap process relies on elevated privileges to perform this task. Two versions of the bootstrap process exist; a code-change driven pipeline using AWS CodeBuild and an event-driven state machine using AWS Lambda. If an actor has permissions to change the behavior of the CodeBuild project or the Lambda function, they would be able to escalate their privileges. Prior to version 4.0.0, the bootstrap CodeBuild role provides access to the `sts:AssumeRole` operation without further restrictions. Therefore, it is able to assume into any AWS Account in the AWS Organization with the elevated privileges provided by the cross-account access role. By default, this role is not restricted when it is created by AWS Organizations, providing Administrator level access to the AWS resources in the AWS Account. The patches for this issue are included in `aws-deployment-framework` version 4.0.0. As a temporary mitigation, add a permissions boundary to the roles created by ADF in the management account. The permissions boundary should deny all IAM and STS actions. This permissions boundary should be in place until you upgrade ADF or bootstrap a new account. While the permissions boundary is in place, the account management and bootstrapping of accounts are unable to create, update, or assume into roles. This mitigates the privilege escalation risk, but also disables ADF's ability to create, manage, and bootstrap accounts.
CVE-2024-34768
Last Modified: 15 Apr 2026Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.
CVE-2024-34799
Last Modified: 20 Mar 2025Missing Authorization vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.82.
CVE-2023-48273
Last Modified: 15 Apr 2026Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2.
CVE-2023-52227
Last Modified: 15 Apr 2026Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.
CVE-2024-34804
Last Modified: 15 Apr 2026Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.
CVE-2024-5873
Last Modified: 12 Jun 2024This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-34815
Last Modified: 23 Apr 2026Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.5.
CVE-2023-52224
Last Modified: 15 Apr 2026Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.
CVE-2024-34758
Last Modified: 15 Apr 2026Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.
CVE-2024-34819
Last Modified: 23 Apr 2026Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2.
CVE-2024-23503
Last Modified: 21 Nov 2024Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.6.
CVE-2023-52233
Last Modified: 4 Jun 2025Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.
CVE-2024-34821
Last Modified: 23 Apr 2026Missing Authorization vulnerability in Anssi Laitila Contact List contact-list.This issue affects Contact List: from n/a through <= 2.9.87.
CVE-2024-34753
Last Modified: 21 Nov 2024Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
CVE-2023-51519
Last Modified: 28 Apr 2026Missing Authorization vulnerability in Soliloquy Team Slider by Soliloquy.This issue affects Slider by Soliloquy: from n/a through 2.7.2.
CVE-2024-32144
Last Modified: 21 Nov 2024Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14.
CVE-2024-5812
Last Modified: 11 Feb 2025A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
CVE-2024-5813
Last Modified: 11 Feb 2025A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
CVE-2024-23521
Last Modified: 21 Nov 2024Missing Authorization vulnerability in Happyforms.This issue affects Happyforms: from n/a through 1.25.10.
CVE-2023-51682
Last Modified: 21 Nov 2024Missing Authorization vulnerability in ibericode MC4WP.This issue affects MC4WP: from n/a through 4.9.9.
CVE-2024-34822
Last Modified: 21 Nov 2024Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.
