CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/fadump: Move fadump_cma_init to setup_arch() after initmem_init() During early init CMA_MIN_ALIGNMENT_BYTES can be PAGE_SIZE, since …

Dec 28, 2024
CVE-2024-56676
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: testing: Initialize some variables annoteded with _free() Variables annotated with __free() need to be …

Dec 28, 2024
CVE-2023-52718
6.4 MEDIUM

A connection hijacking vulnerability exists in some Huawei home routers. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-34408) This vulnerability has …

Dec 28, 2024
CVE-2023-7266
7.5 HIGH

Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been …

Dec 28, 2024
CVE-2023-7263
7.3 HIGH

Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability …

Dec 28, 2024
CVE-2022-48470
4.0 MEDIUM

Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This …

Dec 28, 2024
CVE-2021-37000
7.7 HIGH

Some Huawei wearables have a permission management vulnerability.

Dec 28, 2024
CVE-2021-22484
7.5 HIGH

Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful exploitation of this vulnerability may cause a server …

Dec 28, 2024
CVE-2020-1824
3.7 LOW

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The …

Dec 28, 2024
CVE-2020-1823
3.7 LOW

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The …

Dec 28, 2024
CVE-2020-1822
3.7 LOW

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The …

Dec 28, 2024
CVE-2020-1821
3.7 LOW

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The …

Dec 28, 2024
CVE-2020-1820
3.7 LOW

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The …

Dec 28, 2024
CVE-2024-46973
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Dec 28, 2024
CVE-2024-46972
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Dec 28, 2024
CVE-2024-43705
7.8 HIGH

Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only system files that have been mapped …

Dec 28, 2024
CVE-2024-54775
4.8 MEDIUM

Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /admin/auth/extensions.

Dec 27, 2024
CVE-2024-54774
4.8 MEDIUM

Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.

Dec 27, 2024
CVE-2024-50714
7.5 HIGH

A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via a crafted script to the /FB/getFbVideoSource.php …

Dec 27, 2024
CVE-2024-50717
9.8 CRITICAL

SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component.

Dec 27, 2024
CVE-2024-50716
9.8 CRITICAL

SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component.

Dec 27, 2024
CVE-2024-50715
7.5 HIGH

An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in …

Dec 27, 2024
CVE-2024-50713
9.8 CRITICAL

SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.

Dec 27, 2024
CVE-2024-56732
8.8 HIGH

HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.

Dec 27, 2024
CVE-2024-54454
5.3 MEDIUM

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink …

Dec 27, 2024
CVE-2024-54453
7.5 HIGH

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet …

Dec 27, 2024
CVE-2024-54452
4.9 MEDIUM

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do …

Dec 27, 2024
CVE-2024-54451
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote attackers …

Dec 27, 2024
CVE-2024-54450
9.4 CRITICAL

An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) …

Dec 27, 2024
CVE-2024-39025
7.5 HIGH

Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

Dec 27, 2024
CVE-2024-12991
3.5 LOW

A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as problematic. This vulnerability affects unknown code of …

Dec 27, 2024
CVE-2024-53476
5.9 MEDIUM

A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the …

Dec 27, 2024
CVE-2024-50945
7.5 HIGH

An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.

Dec 27, 2024
CVE-2024-50944
9.8 CRITICAL

Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart …

Dec 27, 2024
CVE-2024-12990
4.3 MEDIUM

A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown part of the file /user/admin-verify of the …

Dec 27, 2024
CVE-2024-12989
5.3 MEDIUM

A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of the …

Dec 27, 2024
CVE-2024-12988
7.3 HIGH

A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the …

Dec 27, 2024
CVE-2024-56509
8.6 HIGH

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow …

Dec 27, 2024
CVE-2024-56508
7.6 HIGH

LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerability exists in the LinkAce. This issue …

Dec 27, 2024
CVE-2024-56507
4.6 MEDIUM

LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scripting (XSS) vulnerability exists in the LinkAce. …

Dec 27, 2024
CVE-2024-12987
7.3 HIGH KEV

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of …

Dec 27, 2024
CVE-2024-12986
7.3 HIGH

A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file …

Dec 27, 2024
CVE-2024-12856
7.2 HIGH

The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and …

Dec 27, 2024
CVE-2024-56675
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors Uprobes always use bpf_prog_run_array_uprobe() under tasks-trace-RCU protection. …

Dec 27, 2024
CVE-2024-56674
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocation point When virtnet_close is followed by virtnet_open, some TX completions can …

Dec 27, 2024
CVE-2024-56673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Do not call pmd dtor on vmemmap page table teardown The vmemmap's, which …

Dec 27, 2024
CVE-2024-56672
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix UAF in blkcg_unpin_online() blkcg_unpin_online() walks up the blkcg hierarchy putting the online pin. …

Dec 27, 2024
CVE-2024-56671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: graniterapids: Fix vGPIO driver crash Move setting irq_chip.name from probe() function to the initialization …

Dec 27, 2024
CVE-2024-56670
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer Considering …

Dec 27, 2024
CVE-2024-56669
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Remove cache tags before disabling ATS The current implementation removes cache tags after disabling …

Dec 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.