CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10881
6.4 MEDIUM

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due …

Dec 5, 2024
CVE-2024-54014
3.6 LOW

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier …

Dec 5, 2024
CVE-2024-12188
7.3 HIGH

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 5, 2024
CVE-2024-12187
7.3 HIGH

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Dec 5, 2024
CVE-2024-54221
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking.This issue affects FAT Services Booking: from …

Dec 5, 2024
CVE-2024-12186
5.3 MEDIUM

A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of …

Dec 5, 2024
CVE-2024-12185
5.3 MEDIUM

A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Administrator Login …

Dec 5, 2024
CVE-2018-9463
6.7 MEDIUM

In sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Dec 5, 2024
CVE-2018-9462
6.7 MEDIUM

In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Dec 5, 2024
CVE-2018-9439
6.7 MEDIUM

In __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the …

Dec 5, 2024
CVE-2018-9416
6.7 MEDIUM

In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with …

Dec 5, 2024
CVE-2018-9408
4.4 MEDIUM

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a …

Dec 5, 2024
CVE-2018-9407
5.5 MEDIUM

In emmc_rpmb_ioctl of emmc_rpmb.c, there is an Information Disclosure due to a Missing Bounds Check. This could lead to Information Disclosure of kernel data.

Dec 5, 2024
CVE-2018-9404
6.7 MEDIUM

In oemCallback of ril.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Dec 5, 2024
CVE-2018-9403
6.7 MEDIUM

In the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local …

Dec 5, 2024
CVE-2018-9402
7.8 HIGH

In multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges in the …

Dec 5, 2024
CVE-2018-9400
6.7 MEDIUM

In gt1x_debug_write_proc and gt1x_tool_write of drivers/input/touchscreen/mediatek/GT1151/gt1x_generic.c and gt1x_tools.c, there is a possible out of bounds write due to a missing bounds check. This could lead …

Dec 5, 2024
CVE-2018-9399
6.7 MEDIUM

In /proc/driver/wmt_dbg driver, there are several possible out of bounds writes. These could lead to local escalation of privilege with System execution privileges needed. User …

Dec 5, 2024
CVE-2018-9398
6.7 MEDIUM

In fm_set_stat of mediatek FM radio driver, there is a possible OOB write due to improper input validation. This could lead to local escalation of …

Dec 5, 2024
CVE-2018-9397
6.7 MEDIUM

In WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB write due to a missing bounds check. This could lead to local escalation …

Dec 5, 2024
CVE-2024-53982

ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Zoo-Project Echo example. The Echo example available by default …

Dec 4, 2024
CVE-2024-12183
3.5 LOW

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP …

Dec 4, 2024
CVE-2024-12182
3.5 LOW

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. …

Dec 4, 2024
CVE-2024-12181
3.5 LOW

A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component …

Dec 4, 2024
CVE-2024-12180
3.5 LOW

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/article_add.php. The manipulation of the argument …

Dec 4, 2024
CVE-2018-9396
6.7 MEDIUM

In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to …

Dec 4, 2024
CVE-2024-54675
6.1 MEDIUM

app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.

Dec 4, 2024
CVE-2024-54674
6.1 MEDIUM

app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format.

Dec 4, 2024
CVE-2024-51210
5.3 MEDIUM

Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a document and all content …

Dec 4, 2024
CVE-2024-50947
7.5 HIGH

An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service (DoS) via a crafted request.

Dec 4, 2024
CVE-2024-39219
8.8 HIGH

An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to …

Dec 4, 2024
CVE-2024-38829
3.7 LOW

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from …

Dec 4, 2024
CVE-2024-48453
9.8 CRITICAL

An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function

Dec 4, 2024
CVE-2024-12196
6.5 MEDIUM

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without …

Dec 4, 2024
CVE-2024-12151
5.0 MEDIUM

Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.

Dec 4, 2024
CVE-2024-12149
8.1 HIGH

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary …

Dec 4, 2024
CVE-2024-12148
4.3 MEDIUM

Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

Dec 4, 2024
CVE-2024-12147
6.5 MEDIUM

A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Dec 4, 2024
CVE-2018-9395
6.7 MEDIUM

In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_vendor.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of …

Dec 4, 2024
CVE-2018-9394
6.7 MEDIUM

In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System …

Dec 4, 2024
CVE-2018-9393
6.7 MEDIUM

In procfile_write of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_proc.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with …

Dec 4, 2024
CVE-2018-9392
6.7 MEDIUM

In get_binary of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/data_coder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Dec 4, 2024
CVE-2024-52676
5.4 MEDIUM

Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/home.php.

Dec 4, 2024
CVE-2024-39163
8.8 HIGH

binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.

Dec 4, 2024
CVE-2024-20397
5.2 MEDIUM

A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local …

Dec 4, 2024
CVE-2024-54134

A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker to publish unauthorized and …

Dec 4, 2024
CVE-2024-54132

The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in …

Dec 4, 2024
CVE-2024-54002
5.3 MEDIUM

Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the …

Dec 4, 2024
CVE-2024-53614
6.5 MEDIUM

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.

Dec 4, 2024
CVE-2024-37575
7.5 HIGH

The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Dec 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.