CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53842
9.8 CRITICAL

In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jan 3, 2025
CVE-2024-53841
7.8 HIGH

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution …

Jan 3, 2025
CVE-2024-53840
7.8 HIGH

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges …

Jan 3, 2025
CVE-2024-53839
5.5 MEDIUM

In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jan 3, 2025
CVE-2024-53838
7.8 HIGH

In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jan 3, 2025
CVE-2024-53837
7.8 HIGH

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-53836
6.7 MEDIUM

In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-53835
7.8 HIGH

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges …

Jan 3, 2025
CVE-2024-53834
7.5 HIGH

In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure …

Jan 3, 2025
CVE-2024-53833
7.8 HIGH

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-47032
7.8 HIGH

In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Jan 3, 2025
CVE-2024-11624
7.8 HIGH

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no …

Jan 3, 2025
CVE-2025-0176
6.3 MEDIUM

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown …

Jan 3, 2025
CVE-2025-0175
3.5 LOW

A vulnerability was found in code-projects Online Shop 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view.php. The …

Jan 3, 2025
CVE-2025-0174
6.3 MEDIUM

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been classified as critical. This affects an unknown part …

Jan 3, 2025
CVE-2024-43769
7.8 HIGH

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. …

Jan 3, 2025
CVE-2024-43768
7.8 HIGH

In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-43767
8.8 HIGH

In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remote code execution with no additional …

Jan 3, 2025
CVE-2024-43764
7.8 HIGH

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional …

Jan 3, 2025
CVE-2024-43762
7.8 HIGH

In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. …

Jan 3, 2025
CVE-2024-43097
7.8 HIGH

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-43077
7.8 HIGH

In DevmemValidateFlags of devicemem_server.c , there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-8447
5.9 MEDIUM

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds …

Jan 2, 2025
CVE-2024-48197
4.7 MEDIUM

Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.

Jan 2, 2025
CVE-2025-0173
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jan 2, 2025
CVE-2024-56199
5.2 MEDIUM

phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an attacker can inject malicious HTML …

Jan 2, 2025
CVE-2024-11717

Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they are sent to the server …

Jan 2, 2025
CVE-2024-11716

While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows …

Jan 2, 2025
CVE-2025-0172
6.3 MEDIUM

A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 2, 2025
CVE-2024-9950
7.8 HIGH

A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.

Jan 2, 2025
CVE-2024-56414
5.5 MEDIUM

Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

Jan 2, 2025
CVE-2024-56413
6.1 MEDIUM

Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

Jan 2, 2025
CVE-2024-55543
7.8 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

Jan 2, 2025
CVE-2024-55542
4.4 MEDIUM

Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before …

Jan 2, 2025
CVE-2024-55541
6.1 MEDIUM

Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build …

Jan 2, 2025
CVE-2024-55540
7.8 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

Jan 2, 2025
CVE-2024-12907

Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent to /CMSMessages/AccessDenied.aspx endpoint. Notably, …

Jan 2, 2025
CVE-2023-23672
5.4 MEDIUM

Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.

Jan 2, 2025
CVE-2022-47601
5.3 MEDIUM

Missing Authorization vulnerability in JoomUnited WP Table Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Table Manager: from n/a through 3.5.2.

Jan 2, 2025
CVE-2022-45811
5.4 MEDIUM

Missing Authorization vulnerability in WeyHan Ng Post Teaser.This issue affects Post Teaser: from n/a through 4.1.5.

Jan 2, 2025
CVE-2025-0171
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Chat System 1.0. Affected is an unknown function of the file /admin/deleteuser.php. The manipulation …

Jan 2, 2025
CVE-2024-56137
6.8 MEDIUM

MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). …

Jan 2, 2025
CVE-2024-55538
4.0 MEDIUM

Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build …

Jan 2, 2025
CVE-2024-49385
5.5 MEDIUM

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (Windows) …

Jan 2, 2025
CVE-2023-48758
7.1 HIGH

Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.2.4.

Jan 2, 2025
CVE-2023-48739
5.3 MEDIUM

Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: …

Jan 2, 2025
CVE-2023-47807
4.3 MEDIUM

Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through <= 1.2.12.

Jan 2, 2025
CVE-2023-47778
4.3 MEDIUM

Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control luckywp-scripts-control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through …

Jan 2, 2025
CVE-2023-45633
6.5 MEDIUM

Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IMPress Listings: from n/a through 2.6.2.

Jan 2, 2025
CVE-2023-45272
5.4 MEDIUM

Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map Builder for …

Jan 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.