| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31477 | Hig | 0.47 | 7.2 | 0.01 | May 14, 2024 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | ||
| CVE-2024-31476 | Hig | 0.47 | 7.2 | 0.01 | May 14, 2024 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | ||
| CVE-2024-31475 | Hig | 0.53 | 8.2 | 0.00 | May 14, 2024 | There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system,… | ||
| CVE-2024-31474 | Hig | 0.53 | 8.2 | 0.00 | May 14, 2024 | There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead… | ||
| CVE-2023-33327 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2024 | Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2. | ||
| CVE-2024-31556 | Hig | 0.44 | 7.8 | 0.00 | May 14, 2024 | An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function. | ||
| CVE-2022-28132 | Hig | 0.47 | 7.2 | 0.01 | May 14, 2024 | The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can… | ||
| CVE-2020-26312 | Hig | 0.53 | 8.1 | 0.00 | May 14, 2024 | Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the … | ||
| CVE-2024-32465 | Hig | 0.00 | 7.3 | 0.01 | May 14, 2024 | Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source… | ||
| CVE-2021-22280 | Hig | 0.47 | 7.2 | 0.00 | May 14, 2024 | Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product. | ||
| CVE-2024-3676 | Hig | 0.49 | 7.5 | 0.00 | May 14, 2024 | The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's… | ||
| CVE-2024-32004 | Hig | 0.00 | 8.1 | 0.01 | May 14, 2024 | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions… | ||
| CVE-2024-2637 | Hig | 0.47 | 7.2 | 0.00 | May 14, 2024 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial… | ||
| CVE-2024-4777 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2024 | Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox… | ||
| CVE-2024-4776 | Hig | 0.53 | 8.2 | 0.00 | May 14, 2024 | A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126. | ||
| CVE-2024-4773 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2024 | When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126. | ||
| CVE-2024-4771 | Hig | 0.56 | 8.6 | 0.01 | May 14, 2024 | A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126. | ||
| CVE-2024-4770 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2024 | When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. | ||
| CVE-2024-4765 | Hig | 0.53 | 8.1 | 0.00 | May 14, 2024 | Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for… | ||
| CVE-2024-4367 | Hig | 0.59 | 8.8 | 0.73 | May 14, 2024 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. | ||
| CVE-2024-27110 | Hig | 0.55 | 8.4 | 0.00 | May 14, 2024 | Elevation of privilege vulnerability in GE HealthCare EchoPAC products | ||
| CVE-2024-31491 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2024 | A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests. | ||
| CVE-2024-30051 | Hig | 0.69 | 7.8 | 0.06 | KEV | May 14, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2024-30049 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | ||
| CVE-2024-30048 | Hig | 0.49 | 7.6 | 0.01 | May 14, 2024 | Dynamics 365 Customer Insights Spoofing Vulnerability | ||
| CVE-2024-30047 | Hig | 0.49 | 7.6 | 0.01 | May 14, 2024 | Dynamics 365 Customer Insights Spoofing Vulnerability | ||
| CVE-2024-30044 | Hig | 0.54 | 7.2 | 0.84 | May 14, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-30042 | Hig | 0.51 | 7.8 | 0.02 | May 14, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-30040 | Hig | 0.70 | 8.8 | 0.04 | KEV | May 14, 2024 | Windows MSHTML Platform Security Feature Bypass Vulnerability | |
| CVE-2024-30038 | Hig | 0.54 | 7.8 | 0.03 | May 14, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-30035 | Hig | 0.51 | 7.8 | 0.04 | May 14, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2024-30033 | Hig | 0.46 | 7.0 | 0.01 | May 14, 2024 | Windows Search Service Elevation of Privilege Vulnerability | ||
| CVE-2024-30032 | Hig | 0.51 | 7.8 | 0.05 | May 14, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2024-30031 | Hig | 0.51 | 7.8 | 0.00 | May 14, 2024 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | ||
| CVE-2024-30030 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-30029 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30028 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-30027 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | NTFS Elevation of Privilege Vulnerability | ||
| CVE-2024-30025 | Hig | 0.51 | 7.8 | 0.04 | May 14, 2024 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-30024 | Hig | 0.49 | 7.5 | 0.02 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30023 | Hig | 0.49 | 7.5 | 0.02 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30022 | Hig | 0.49 | 7.5 | 0.02 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30020 | Hig | 0.53 | 8.1 | 0.01 | May 14, 2024 | Windows Cryptographic Services Remote Code Execution Vulnerability | ||
| CVE-2024-30018 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-30017 | Hig | 0.57 | 8.8 | 0.02 | May 14, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2024-30015 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30014 | Hig | 0.49 | 7.5 | 0.01 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30010 | Hig | 0.57 | 8.8 | 0.02 | May 14, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2024-30009 | Hig | 0.57 | 8.8 | 0.02 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-30007 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2024 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
- risk 0.47cvss 7.2epss 0.01
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
- risk 0.47cvss 7.2epss 0.01
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
- risk 0.53cvss 8.2epss 0.00
There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system,…
- risk 0.53cvss 8.2epss 0.00
There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead…
- risk 0.57cvss 8.8epss 0.01
Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.
- risk 0.44cvss 7.8epss 0.00
An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.
- risk 0.47cvss 7.2epss 0.01
The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can…
- risk 0.53cvss 8.1epss 0.00
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the …
- risk 0.00cvss 7.3epss 0.01
Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source…
- risk 0.47cvss 7.2epss 0.00
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.
- risk 0.49cvss 7.5epss 0.00
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's…
- risk 0.00cvss 8.1epss 0.01
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions…
- risk 0.47cvss 7.2epss 0.00
An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial…
- risk 0.57cvss 8.8epss 0.01
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox…
- risk 0.53cvss 8.2epss 0.00
A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.
- risk 0.49cvss 7.5epss 0.01
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.
- risk 0.56cvss 8.6epss 0.01
A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.
- risk 0.57cvss 8.8epss 0.01
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- risk 0.53cvss 8.1epss 0.00
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for…
- risk 0.59cvss 8.8epss 0.73
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- risk 0.55cvss 8.4epss 0.00
Elevation of privilege vulnerability in GE HealthCare EchoPAC products
- risk 0.57cvss 8.8epss 0.01
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
- risk 0.69cvss 7.8epss 0.06
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
- risk 0.49cvss 7.6epss 0.01
Dynamics 365 Customer Insights Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Dynamics 365 Customer Insights Spoofing Vulnerability
- risk 0.54cvss 7.2epss 0.84
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.70cvss 8.8epss 0.04
Windows MSHTML Platform Security Feature Bypass Vulnerability
- risk 0.54cvss 7.8epss 0.03
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Search Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.05
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
NTFS Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Cryptographic Services Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Microsoft Brokering File System Elevation of Privilege Vulnerability