CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20847
4.0 MEDIUM

Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.

Apr 2, 2024
CVE-2024-20846
5.9 MEDIUM

Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

Apr 2, 2024
CVE-2024-20843
5.6 MEDIUM

Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Apr 2, 2024
CVE-2024-20842
4.2 MEDIUM

Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

Apr 2, 2024
CVE-2024-3148
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in DedeCMS 5.7.112. This issue affects some unknown processing of the file dede/makehtml_archives_action.php. The manipulation …

Apr 2, 2024
CVE-2024-3147
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/makehtml_map.php. The manipulation leads to cross-site request …

Apr 2, 2024
CVE-2024-3146
4.3 MEDIUM

A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/makehtml_rss_action.php. The manipulation leads to cross-site …

Apr 2, 2024
CVE-2024-3145
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/makehtml_js_action.php. …

Apr 2, 2024
CVE-2024-3144
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/makehtml_spec.php. …

Apr 2, 2024
CVE-2024-3143
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/member_rank.php. The manipulation leads …

Apr 2, 2024
CVE-2024-3142
4.3 MEDIUM

A vulnerability was found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This issue affects some unknown processing of the component …

Apr 2, 2024
CVE-2024-27334
5.5 MEDIUM

Kofax Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax …

Apr 2, 2024
CVE-2024-3139
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users …

Apr 1, 2024
CVE-2024-27333
5.5 MEDIUM

Kofax Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax …

Apr 1, 2024
CVE-2024-3165
4.5 MEDIUM

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it …

Apr 1, 2024
CVE-2024-3164
4.5 MEDIUM

In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible …

Apr 1, 2024
CVE-2024-27329
5.5 MEDIUM

PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27328
5.5 MEDIUM

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27326
5.5 MEDIUM

PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27325
5.5 MEDIUM

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27324
5.5 MEDIUM

PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-29435
4.1 MEDIUM

An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.

Apr 1, 2024
CVE-2023-48906
4.3 MEDIUM

Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.

Apr 1, 2024
CVE-2024-3135
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized …

Apr 1, 2024
CVE-2024-3131
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 1, 2024
CVE-2024-28232
6.2 MEDIUM

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which …

Apr 1, 2024
CVE-2024-3129
6.3 MEDIUM

A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 1, 2024
CVE-2024-30863
6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.

Apr 1, 2024
CVE-2024-30861
5.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.

Apr 1, 2024
CVE-2024-30866
5.4 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

Apr 1, 2024
CVE-2024-30864
6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.

Apr 1, 2024
CVE-2024-26655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we don't …

Apr 1, 2024
CVE-2023-43515
6.6 MEDIUM

Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.

Apr 1, 2024
CVE-2023-33111
5.5 MEDIUM

Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.

Apr 1, 2024
CVE-2024-31099
6.4 MEDIUM

Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through …

Apr 1, 2024
CVE-2024-30872
5.1 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

Apr 1, 2024
CVE-2024-3130
5.7 MEDIUM

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm …

Apr 1, 2024
CVE-2024-25080
4.7 MEDIUM

WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.

Apr 1, 2024
CVE-2016-15038
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. …

Apr 1, 2024
CVE-2024-2278
6.1 MEDIUM

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to …

Apr 1, 2024
CVE-2024-2263
4.8 MEDIUM

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting …

Apr 1, 2024
CVE-2024-2262
4.7 MEDIUM

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary …

Apr 1, 2024
CVE-2024-1526
5.3 MEDIUM

The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta …

Apr 1, 2024
CVE-2024-20055
6.3 MEDIUM

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Apr 1, 2024
CVE-2024-20054
6.6 MEDIUM

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System …

Apr 1, 2024
CVE-2024-20052
4.4 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20050
4.4 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20049
4.4 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20048
6.2 MEDIUM

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. …

Apr 1, 2024
CVE-2024-20047
5.4 MEDIUM

In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution …

Apr 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.