CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32900
7.8 HIGH

In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of privilege from hal_camera_default …

Jun 13, 2024
CVE-2024-32899
7.0 HIGH

In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-32898
4.7 MEDIUM

In ProtocolCellIdentityParserV4::Parse() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-32897
5.9 MEDIUM

In ProtocolCdmaCallWaitingIndAdapter::GetCwInfo() of protocolsmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Jun 13, 2024
CVE-2024-32896
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-32895
7.8 HIGH

In BCMFASTPATH of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jun 13, 2024
CVE-2024-32894
7.5 HIGH

In bc_get_converted_received_bearer of bc_utilities.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Jun 13, 2024
CVE-2024-32893
5.5 MEDIUM

In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no …

Jun 13, 2024
CVE-2024-32892
7.8 HIGH

In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional …

Jun 13, 2024
CVE-2024-32891
7.0 HIGH

In sec_media_unprotect of media.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-29787
7.8 HIGH

In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-29786
9.8 CRITICAL

In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 13, 2024
CVE-2024-29785
5.5 MEDIUM

In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution …

Jun 13, 2024
CVE-2024-29784
7.8 HIGH

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-29781
7.5 HIGH

In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with …

Jun 13, 2024
CVE-2024-29780
5.5 MEDIUM

In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local information disclosure with no …

Jun 13, 2024
CVE-2024-29778
4.7 MEDIUM

In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-5952
6.5 MEDIUM

Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 …

Jun 13, 2024
CVE-2024-5951
6.5 MEDIUM

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics …

Jun 13, 2024
CVE-2024-5950
8.8 HIGH

Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …

Jun 13, 2024
CVE-2024-5949
6.5 MEDIUM

Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Deep …

Jun 13, 2024
CVE-2024-5948
8.8 HIGH

Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Jun 13, 2024
CVE-2024-5947
6.5 MEDIUM

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep …

Jun 13, 2024
CVE-2024-5924
8.8 HIGH

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User …

Jun 13, 2024
CVE-2024-4696
7.5 HIGH

A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a …

Jun 13, 2024
CVE-2024-38313
4.3 MEDIUM

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address …

Jun 13, 2024
CVE-2024-38312
6.5 MEDIUM

When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination …

Jun 13, 2024
CVE-2024-38083
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 13, 2024
CVE-2024-30058
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 13, 2024
CVE-2024-30057
5.4 MEDIUM

Microsoft Edge for iOS Spoofing Vulnerability

Jun 13, 2024
CVE-2024-37635
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

Jun 13, 2024
CVE-2024-37634
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

Jun 13, 2024
CVE-2024-37633
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg

Jun 13, 2024
CVE-2024-37632
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

Jun 13, 2024
CVE-2024-37631
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.

Jun 13, 2024
CVE-2024-36589
4.3 MEDIUM

An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.

Jun 13, 2024
CVE-2024-36588
6.5 MEDIUM

An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

Jun 13, 2024
CVE-2024-36587
7.8 HIGH

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

Jun 13, 2024
CVE-2024-36586
8.8 HIGH

An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.

Jun 13, 2024
CVE-2024-38285

Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.

Jun 13, 2024
CVE-2024-38284

Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.

Jun 13, 2024
CVE-2024-38283

Sensitive customer information is stored in the device without encryption.

Jun 13, 2024
CVE-2024-38282

Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or …

Jun 13, 2024
CVE-2024-37630
8.8 HIGH

D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

Jun 13, 2024
CVE-2024-37029
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 13, 2024
CVE-2024-37022
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipulate memory, resulting in execution of arbitrary code.

Jun 13, 2024
CVE-2024-36760
7.5 HIGH

A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : …

Jun 13, 2024
CVE-2024-38281
9.8 CRITICAL

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

Jun 13, 2024
CVE-2024-38280
4.6 MEDIUM

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data …

Jun 13, 2024
CVE-2024-38279
4.6 MEDIUM

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.