CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27623
5.9 MEDIUM

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

Mar 5, 2024
CVE-2024-2188
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a …

Mar 5, 2024
CVE-2023-45600
5.6 MEDIUM

A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. …

Mar 5, 2024
CVE-2023-45599
5.5 MEDIUM

A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker …

Mar 5, 2024
CVE-2023-45598
5.3 MEDIUM

A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. …

Mar 5, 2024
CVE-2023-45597
5.9 MEDIUM

A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows …

Mar 5, 2024
CVE-2023-45596
5.3 MEDIUM

A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. …

Mar 5, 2024
CVE-2023-45595
5.9 MEDIUM

A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to upload …

Mar 5, 2024
CVE-2023-45594
6.8 MEDIUM

A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/from the …

Mar 5, 2024
CVE-2023-45593
6.8 MEDIUM

A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows …

Mar 5, 2024
CVE-2023-45592
6.8 MEDIUM

A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root …

Mar 5, 2024
CVE-2022-48630
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced …

Mar 5, 2024
CVE-2022-48629
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct …

Mar 5, 2024
CVE-2024-26337
4.3 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.

Mar 5, 2024
CVE-2024-26335
5.5 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

Mar 5, 2024
CVE-2024-26334
6.2 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib/action/actioncompiler.c.

Mar 5, 2024
CVE-2024-26333
5.5 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.

Mar 5, 2024
CVE-2024-20833
4.1 MEDIUM

Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory …

Mar 5, 2024
CVE-2024-20841
5.1 MEDIUM

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

Mar 5, 2024
CVE-2024-20840
5.7 MEDIUM

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using …

Mar 5, 2024
CVE-2024-20839
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to …

Mar 5, 2024
CVE-2024-20838
6.8 MEDIUM

Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20837
5.3 MEDIUM

Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own …

Mar 5, 2024
CVE-2024-20835
4.0 MEDIUM

Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.

Mar 5, 2024
CVE-2024-20832
6.4 MEDIUM

Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20831
6.4 MEDIUM

Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20830
5.3 MEDIUM

Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

Mar 5, 2024
CVE-2024-20829
5.4 MEDIUM

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

Mar 5, 2024
CVE-2023-52432
5.9 MEDIUM

Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.

Mar 5, 2024
CVE-2024-22383
6.2 MEDIUM

Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under …

Mar 5, 2024
CVE-2024-21838
6.8 MEDIUM

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection …

Mar 5, 2024
CVE-2024-1782
6.1 MEDIUM

The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' parameter in all versions up to, and including, 1.0 …

Mar 5, 2024
CVE-2024-1769
5.3 MEDIUM

The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description data. …

Mar 5, 2024
CVE-2024-1478
5.3 MEDIUM

The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This …

Mar 5, 2024
CVE-2024-1381
6.5 MEDIUM

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Mar 5, 2024
CVE-2024-1285
6.5 MEDIUM

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Mar 5, 2024
CVE-2024-1178
5.3 MEDIUM

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 5, 2024
CVE-2024-1095
5.3 MEDIUM

The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Mar 5, 2024
CVE-2024-1093
5.3 MEDIUM

The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic() function hooked …

Mar 5, 2024
CVE-2024-1088
5.3 MEDIUM

The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the …

Mar 5, 2024
CVE-2024-0698
6.4 MEDIUM

The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due …

Mar 5, 2024
CVE-2023-49969
4.3 MEDIUM

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

Mar 5, 2024
CVE-2023-41829
5.0 MEDIUM

An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

Mar 4, 2024
CVE-2023-41827
5.1 MEDIUM

An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on …

Mar 4, 2024
CVE-2024-2168
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 4, 2024
CVE-2024-1319
4.3 MEDIUM

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any …

Mar 4, 2024
CVE-2024-1316
6.5 MEDIUM

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor …

Mar 4, 2024
CVE-2021-47108
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check …

Mar 4, 2024
CVE-2021-47105
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: xsk: return xsk buffers back to pool when cleaning the ring Currently we only …

Mar 4, 2024
CVE-2021-47104
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/qib: Fix memory leak in qib_user_sdma_queue_pkts() The wrong goto label was used for the error …

Mar 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.