CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34641
5.1 MEDIUM

Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

Sep 4, 2024
CVE-2024-34640
3.3 LOW

Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

Sep 4, 2024
CVE-2024-34639
4.6 MEDIUM

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

Sep 4, 2024
CVE-2024-34638
6.7 MEDIUM

Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

Sep 4, 2024
CVE-2024-34637
6.2 MEDIUM

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 …

Sep 4, 2024
CVE-2024-8298
6.2 MEDIUM

Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-7950
9.8 CRITICAL

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary …

Sep 4, 2024
CVE-2024-45449
5.1 MEDIUM

Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45448
4.1 MEDIUM

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45447
4.4 MEDIUM

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45446
5.5 MEDIUM

Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45445
4.0 MEDIUM

Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45444
5.5 MEDIUM

Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45443
6.1 MEDIUM

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Sep 4, 2024
CVE-2024-39921
7.5 HIGH

Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. …

Sep 4, 2024
CVE-2024-45450
4.0 MEDIUM

Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45442
5.1 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45441
6.2 MEDIUM

Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-42039
4.3 MEDIUM

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-41927
4.6 MEDIUM

Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials …

Sep 4, 2024
CVE-2024-41716
8.1 HIGH

Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may …

Sep 4, 2024
CVE-2024-8362
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 3, 2024
CVE-2024-7970
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Sep 3, 2024
CVE-2024-45620
3.9 LOW

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the …

Sep 3, 2024
CVE-2024-45619
4.3 MEDIUM

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-45618
3.9 LOW

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with …

Sep 3, 2024
CVE-2024-45617
3.9 LOW

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-45616
3.9 LOW

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-45615
3.9 LOW

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as …

Sep 3, 2024
CVE-2024-44809
9.8 CRITICAL

A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The issue arises from improper sanitization of user …

Sep 3, 2024
CVE-2024-45394
8.8 HIGH

Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using …

Sep 3, 2024
CVE-2024-41433
9.8 CRITICAL

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Sep 3, 2024
CVE-2024-8399
4.7 MEDIUM

Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.

Sep 3, 2024
CVE-2024-4629
6.5 MEDIUM

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple …

Sep 3, 2024
CVE-2024-45678
4.2 MEDIUM

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires …

Sep 3, 2024
CVE-2024-45391
7.5 HIGH

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search …

Sep 3, 2024
CVE-2024-45390
7.3 HIGH

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has …

Sep 3, 2024
CVE-2024-45389
6.4 MEDIUM

Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This …

Sep 3, 2024
CVE-2024-45180
5.4 MEDIUM

SquaredUp DS for SCOM 6.2.1.11104 allows XSS.

Sep 3, 2024
CVE-2024-41434
4.3 MEDIUM

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via …

Sep 3, 2024
CVE-2024-45310
3.6 LOW

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, …

Sep 3, 2024
CVE-2024-45307
8.8 HIGH

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able …

Sep 3, 2024
CVE-2024-43803
4.9 MEDIUM

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and …

Sep 3, 2024
CVE-2024-43413
3.5 LOW

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo …

Sep 3, 2024
CVE-2024-41436
7.5 HIGH

ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.

Sep 3, 2024
CVE-2024-41435
7.5 HIGH

YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.

Sep 3, 2024
CVE-2024-7619

Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there …

Sep 3, 2024
CVE-2024-42904
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name …

Sep 3, 2024
CVE-2024-42903
6.5 MEDIUM

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link …

Sep 3, 2024
CVE-2024-42902
8.8 HIGH

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng …

Sep 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.