CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40857
6.1 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, …

Sep 17, 2024
CVE-2024-40856
7.5 HIGH

An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18. An attacker …

Sep 17, 2024
CVE-2024-40852
5.3 MEDIUM

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may …

Sep 17, 2024
CVE-2024-40850
5.5 MEDIUM

A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, …

Sep 17, 2024
CVE-2024-40848
7.5 HIGH

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An attacker …

Sep 17, 2024
CVE-2024-40847
5.5 MEDIUM

The issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may …

Sep 17, 2024
CVE-2024-40846
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. Processing a maliciously crafted video file …

Sep 17, 2024
CVE-2024-40845
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. Processing a maliciously crafted video file …

Sep 17, 2024
CVE-2024-40844
5.5 MEDIUM

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Sequoia 15, macOS …

Sep 17, 2024
CVE-2024-40843
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to modify protected parts of …

Sep 17, 2024
CVE-2024-40842
5.5 MEDIUM

An issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15. An app may be able to access …

Sep 17, 2024
CVE-2024-40841
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. Processing a maliciously crafted …

Sep 17, 2024
CVE-2024-40840
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be …

Sep 17, 2024
CVE-2024-40838
3.3 LOW

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app may …

Sep 17, 2024
CVE-2024-40837
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user …

Sep 17, 2024
CVE-2024-40831
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access a user's …

Sep 17, 2024
CVE-2024-40830
3.3 LOW

This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to enumerate …

Sep 17, 2024
CVE-2024-40826
6.1 MEDIUM

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted …

Sep 17, 2024
CVE-2024-40825
4.4 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with root privileges may be …

Sep 17, 2024
CVE-2024-40801
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. An app may be able to …

Sep 17, 2024
CVE-2024-40797
6.1 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. Visiting a malicious …

Sep 17, 2024
CVE-2024-40791
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 …

Sep 17, 2024
CVE-2024-40790
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in visionOS 2. An app may be able to read sensitive data …

Sep 17, 2024
CVE-2024-40770
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted …

Sep 17, 2024
CVE-2024-27880
5.5 MEDIUM

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, …

Sep 17, 2024
CVE-2024-27879
7.5 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker …

Sep 17, 2024
CVE-2024-27876
5.5 MEDIUM

A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia …

Sep 17, 2024
CVE-2024-27875
5.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. Privacy Indicators for microphone or camera access may …

Sep 17, 2024
CVE-2024-27874
7.5 HIGH

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to …

Sep 17, 2024
CVE-2024-27869
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able …

Sep 17, 2024
CVE-2024-27861
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricted memory.

Sep 17, 2024
CVE-2024-27860
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricted memory.

Sep 17, 2024
CVE-2024-27858
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user …

Sep 17, 2024
CVE-2024-27795
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the …

Sep 17, 2024
CVE-2024-23237
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause a denial-of-service.

Sep 17, 2024
CVE-2024-6685
3.1 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, …

Sep 16, 2024
CVE-2024-4283
6.4 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain …

Sep 16, 2024
CVE-2024-45416
8.1 HIGH

The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory …

Sep 16, 2024
CVE-2024-45415
9.8 CRITICAL

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of …

Sep 16, 2024
CVE-2024-45414
9.8 CRITICAL

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, …

Sep 16, 2024
CVE-2024-45413
8.1 HIGH

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to …

Sep 16, 2024
CVE-2024-8766
6.7 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235, Acronis Cyber Protect …

Sep 16, 2024
CVE-2024-45800
5.0 MEDIUM

Snappymail is an open source web-based email client. SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS in emails. Research discovered that the function …

Sep 16, 2024
CVE-2024-44445

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Sep 16, 2024
CVE-2024-42798
7.6 HIGH

An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take …

Sep 16, 2024
CVE-2024-42796
5.9 MEDIUM

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid …

Sep 16, 2024
CVE-2024-42795
4.2 MEDIUM

An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view …

Sep 16, 2024
CVE-2024-42794
4.7 MEDIUM

Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.

Sep 16, 2024
CVE-2024-34016
6.5 MEDIUM

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235.

Sep 16, 2024
CVE-2024-22013
5.3 MEDIUM

U-Boot environment is read from unauthenticated partition.

Sep 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.