CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33064
8.2 HIGH

Information disclosure while parsing the multiple MBSSID IEs from the beacon.

Oct 7, 2024
CVE-2024-33049
7.5 HIGH

Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

Oct 7, 2024
CVE-2024-23379
6.7 MEDIUM

Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

Oct 7, 2024
CVE-2024-23378
6.7 MEDIUM

Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.

Oct 7, 2024
CVE-2024-23376
6.7 MEDIUM

Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.

Oct 7, 2024
CVE-2024-23375
6.7 MEDIUM

Memory corruption during the network scan request.

Oct 7, 2024
CVE-2024-23374
6.7 MEDIUM

Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.

Oct 7, 2024
CVE-2024-23370
6.7 MEDIUM

Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the …

Oct 7, 2024
CVE-2024-23369
7.8 HIGH

Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.

Oct 7, 2024
CVE-2024-21455
7.8 HIGH

Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

Oct 7, 2024
CVE-2024-47344
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through <= 2.1.5.

Oct 7, 2024
CVE-2024-47335
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit …

Oct 7, 2024
CVE-2024-20103
9.8 CRITICAL

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20102
4.9 MEDIUM

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System …

Oct 7, 2024
CVE-2024-20101
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20100
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20099
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20098
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20097
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20096
4.4 MEDIUM

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20095
4.4 MEDIUM

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20094
7.5 HIGH

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional …

Oct 7, 2024
CVE-2024-20093
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20092
7.8 HIGH

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20091
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20090
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-9565
8.8 HIGH

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file …

Oct 7, 2024
CVE-2024-9564
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation …

Oct 7, 2024
CVE-2024-9563
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. …

Oct 7, 2024
CVE-2024-9562
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads …

Oct 6, 2024
CVE-2024-9561
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads …

Oct 6, 2024
CVE-2024-9560
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file …

Oct 6, 2024
CVE-2024-9559
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The …

Oct 6, 2024
CVE-2024-9558
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation …

Oct 6, 2024
CVE-2024-9557
8.8 HIGH

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The …

Oct 6, 2024
CVE-2024-9556
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation …

Oct 6, 2024
CVE-2024-9555
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the …

Oct 6, 2024
CVE-2024-47650
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Axton WP-WebAuthn wp-webauthn allows Stored XSS.This issue affects WP-WebAuthn: from n/a through <= …

Oct 6, 2024
CVE-2024-47350
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax …

Oct 6, 2024
CVE-2024-47338
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue …

Oct 6, 2024
CVE-2024-45252
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45251
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45250
4.3 MEDIUM

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

Oct 6, 2024
CVE-2024-45249
9.8 CRITICAL

Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Oct 6, 2024
CVE-2024-45248
7.5 HIGH

Multi-DNC – CWE-35: Path Traversal: '.../...//'

Oct 6, 2024
CVE-2024-44040
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware ShiftController Employee Shift Scheduling shiftcontroller allows Stored XSS.This issue affects ShiftController Employee …

Oct 6, 2024
CVE-2024-44039
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from …

Oct 6, 2024
CVE-2024-44037
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Multipurpose Ticket Booking Manager bus-booking-manager allows Stored XSS.This issue affects Multipurpose Ticket …

Oct 6, 2024
CVE-2024-44036
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes kodex-posts-likes allows Stored XSS.This issue affects Kodex Posts …

Oct 6, 2024
CVE-2024-44035
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: …

Oct 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.