CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2018-9421
5.5 MEDIUM

In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure …

Nov 19, 2024
CVE-2018-9420
5.5 MEDIUM

In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Nov 19, 2024
CVE-2018-9419
7.5 HIGH

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 19, 2024
CVE-2018-9417
7.8 HIGH

In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no …

Nov 19, 2024
CVE-2018-9412
5.5 MEDIUM

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional …

Nov 19, 2024
CVE-2018-9411
8.8 HIGH

In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with …

Nov 19, 2024
CVE-2024-52763
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a …

Nov 19, 2024
CVE-2024-52762
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a …

Nov 19, 2024
CVE-2018-9410
5.5 MEDIUM

In analyzeAxes of FontUtils.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Nov 19, 2024
CVE-2018-9365
8.8 HIGH

In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead …

Nov 19, 2024
CVE-2024-52360
7.6 HIGH

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow …

Nov 19, 2024
CVE-2024-52359
4.3 MEDIUM

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due …

Nov 19, 2024
CVE-2024-45422
6.5 MEDIUM

Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.

Nov 19, 2024
CVE-2024-45420
4.3 MEDIUM

Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.

Nov 19, 2024
CVE-2024-45419
8.1 HIGH

Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Nov 19, 2024
CVE-2024-37070
4.3 MEDIUM

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the …

Nov 19, 2024
CVE-2024-1271

Rejected reason: This CVE was previously published at https://bugzilla.redhat.com/show_bug.cgi?id=2262978 but later rejected for the following reason: The flaw requires an attacker to have superuser credentials …

Nov 19, 2024
CVE-2024-11395
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 19, 2024
CVE-2018-9409
7.8 HIGH

In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Nov 19, 2024
CVE-2018-9372
7.8 HIGH

In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation …

Nov 19, 2024
CVE-2018-9371
6.4 MEDIUM

In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient …

Nov 19, 2024
CVE-2018-9370
7.3 HIGH

In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check. This …

Nov 19, 2024
CVE-2018-9369
7.3 HIGH

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution …

Nov 19, 2024
CVE-2018-9368
7.8 HIGH

In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This could lead to local …

Nov 19, 2024
CVE-2018-9367
7.8 HIGH

In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Nov 19, 2024
CVE-2018-9366
7.8 HIGH

In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to …

Nov 19, 2024
CVE-2018-9364
7.5 HIGH

In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User …

Nov 19, 2024
CVE-2018-9348
6.5 MEDIUM

In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional …

Nov 19, 2024
CVE-2024-52759
9.8 CRITICAL

D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.

Nov 19, 2024
CVE-2024-52714
9.8 CRITICAL

Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.

Nov 19, 2024
CVE-2024-51503
8.0 HIGH

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute …

Nov 19, 2024
CVE-2024-50430
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Stored XSS.This issue affects Beaver Builder: from …

Nov 19, 2024
CVE-2024-48694
9.8 CRITICAL

File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.

Nov 19, 2024
CVE-2024-21697
8.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE …

Nov 19, 2024
CVE-2018-9346
5.5 MEDIUM

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Nov 19, 2024
CVE-2018-9345
5.5 MEDIUM

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Nov 19, 2024
CVE-2018-9344
7.8 HIGH

In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with …

Nov 19, 2024
CVE-2018-9341
7.8 HIGH

In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution …

Nov 19, 2024
CVE-2018-9340
5.5 MEDIUM

In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.

Nov 19, 2024
CVE-2018-9339
7.8 HIGH

In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege …

Nov 19, 2024
CVE-2024-53088
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i40e: fix race condition by adding filter's intermediate sync state Fix a race condition in …

Nov 19, 2024
CVE-2024-53087
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix possible exec queue leak in exec IOCTL In a couple of places after …

Nov 19, 2024
CVE-2024-53086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Drop VM dma-resv lock on xe_sync_in_fence_get failure in exec IOCTL Upon failure all locks …

Nov 19, 2024
CVE-2024-53085
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: Lock TPM chip in tpm_pm_suspend() first Setting TPM_CHIP_FLAG_SUSPENDED in the end of tpm_pm_suspend() can …

Nov 19, 2024
CVE-2024-53084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Break an object reference loop When remaining resources are being cleaned up on driver …

Nov 19, 2024
CVE-2024-53083
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: init value of hdr_len/txbuf_len earlier If the read of USB_PDPHY_RX_ACKNOWLEDGE_REG failed, then …

Nov 19, 2024
CVE-2024-53082
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key_length check in virtnet_probe() to avoid possible out of bound …

Nov 19, 2024
CVE-2024-53081
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: ar0521: don't overflow when checking PLL values The PLL checks are comparing 64 bit …

Nov 19, 2024
CVE-2024-53080
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Lock XArray when getting entries for the VM Similar to commit cac075706f29 ("drm/panthor: Fix …

Nov 19, 2024
CVE-2024-53079
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/thp: fix deferred split unqueue naming and locking Recent changes are putting more pressure on …

Nov 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.