CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7849
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, …

Aug 16, 2024
CVE-2024-7845
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 16, 2024
CVE-2024-43378
7.8 HIGH

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning …

Aug 16, 2024
CVE-2024-43374
4.5 MEDIUM

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, …

Aug 16, 2024
CVE-2024-43370
7.2 HIGH

gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dictionary definition files are corrupted. …

Aug 16, 2024
CVE-2024-43369
7.2 HIGH

Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch …

Aug 16, 2024
CVE-2024-7844
3.5 LOW

A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 15, 2024
CVE-2024-7843
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. …

Aug 15, 2024
CVE-2024-7842
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the …

Aug 15, 2024
CVE-2024-7841
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerability affects unknown code of the file /pms/ajax/check_user_name.php. The manipulation …

Aug 15, 2024
CVE-2024-34743
7.8 HIGH

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local …

Aug 15, 2024
CVE-2024-34742
5.5 MEDIUM

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. …

Aug 15, 2024
CVE-2024-34741
7.8 HIGH

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted …

Aug 15, 2024
CVE-2024-34740
7.8 HIGH

In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of …

Aug 15, 2024
CVE-2024-34739
7.8 HIGH

In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation …

Aug 15, 2024
CVE-2024-34738
7.8 HIGH

In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error …

Aug 15, 2024
CVE-2024-34737
7.8 HIGH

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This …

Aug 15, 2024
CVE-2024-34736
7.8 HIGH

In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabled. This could lead to local escalation of privilege with no …

Aug 15, 2024
CVE-2024-34734
7.8 HIGH

In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This …

Aug 15, 2024
CVE-2024-34731
7.0 HIGH

In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with …

Aug 15, 2024
CVE-2024-34727
7.5 HIGH

In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure …

Aug 15, 2024
CVE-2024-31333
7.8 HIGH

In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in …

Aug 15, 2024
CVE-2024-7868
8.2 HIGH

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept …

Aug 15, 2024
CVE-2024-7839
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of …

Aug 15, 2024
CVE-2024-6456

AVEVA Historian Server has a vulnerability, if exploited, could allow a malicious SQL command to execute under the privileges of an interactive Historian REST Interface …

Aug 15, 2024
CVE-2024-43367
7.5 HIGH

Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0.19.0, a wrong assumption made when …

Aug 15, 2024
CVE-2024-43366
7.5 HIGH

zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to …

Aug 15, 2024
CVE-2024-42488
6.8 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and 1.15.8, a race condition in the Cilium agent …

Aug 15, 2024
CVE-2024-42487
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to …

Aug 15, 2024
CVE-2024-7867
6.2 MEDIUM

In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.

Aug 15, 2024
CVE-2024-7866
5.5 MEDIUM

In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.

Aug 15, 2024
CVE-2024-7838
7.3 HIGH

A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 15, 2024
CVE-2024-43357
8.6 HIGH

ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 …

Aug 15, 2024
CVE-2024-42757
9.8 CRITICAL

Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.

Aug 15, 2024
CVE-2024-42476
6.5 MEDIUM

In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent …

Aug 15, 2024
CVE-2024-42475
6.5 MEDIUM

In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can …

Aug 15, 2024
CVE-2024-42472
10.0 CRITICAL

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could …

Aug 15, 2024
CVE-2024-27731
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file …

Aug 15, 2024
CVE-2024-27730
9.8 CRITICAL

Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar …

Aug 15, 2024
CVE-2024-27729
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.

Aug 15, 2024
CVE-2024-27728
6.1 MEDIUM

Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.

Aug 15, 2024
CVE-2024-25633
5.4 MEDIUM

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user …

Aug 15, 2024
CVE-2024-23168
9.8 CRITICAL

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

Aug 15, 2024
CVE-2024-32231
6.3 MEDIUM

Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.

Aug 15, 2024
CVE-2024-22219
6.3 MEDIUM

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via …

Aug 15, 2024
CVE-2024-22218
8.8 HIGH

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submit malicious XML via …

Aug 15, 2024
CVE-2024-22217
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on …

Aug 15, 2024
CVE-2024-42987
7.5 HIGH

Tenda FH1206 v02.03.01.35 was discovered to contain a stack-based buffer overflow vulnerability in the fromPptpUserAdd function. The vulnerability can be triggered via the modino, username, …

Aug 15, 2024
CVE-2024-42986
7.5 HIGH

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a …

Aug 15, 2024
CVE-2024-42985
7.5 HIGH

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a …

Aug 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.