CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-34981
6.7 MEDIUM

Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An …

May 7, 2024
CVE-2021-34976
5.5 MEDIUM

Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34975
7.8 HIGH

Foxit PDF Reader transitionToState Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34974
7.8 HIGH

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34973
5.5 MEDIUM

Foxit PDF Reader PDF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34972
5.5 MEDIUM

Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User …

May 7, 2024
CVE-2021-34971
7.8 HIGH

Foxit PDF Reader JPG2000 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

May 7, 2024
CVE-2021-34970
5.5 MEDIUM

Foxit PDF Reader print Method Use of Externally-Controlled Format String Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations …

May 7, 2024
CVE-2021-34969
5.5 MEDIUM

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User …

May 7, 2024
CVE-2021-34968
7.8 HIGH

Foxit PDF Editor transitionToState Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. …

May 7, 2024
CVE-2021-34967
7.8 HIGH

Foxit PDF Editor Line Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34966
7.8 HIGH

Foxit PDF Editor FileAttachment Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34965
7.8 HIGH

Foxit PDF Editor Squiggly Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34964
7.8 HIGH

Foxit PDF Editor Polygon Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34963
7.8 HIGH

Foxit PDF Editor PolyLine Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34962
7.8 HIGH

Foxit PDF Editor Caret Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34961
7.8 HIGH

Foxit PDF Editor Ink Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34960
7.8 HIGH

Foxit PDF Editor Circle Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34959
7.8 HIGH

Foxit PDF Editor Square Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34958
7.8 HIGH

Foxit PDF Editor Text Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34957
7.8 HIGH

Foxit PDF Editor Highlight Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34956
7.8 HIGH

Foxit PDF Editor Underline Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34955
7.8 HIGH

Foxit PDF Editor Stamp Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34954
7.8 HIGH

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34953
7.8 HIGH

Foxit PDF Reader Annotation Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

May 7, 2024
CVE-2021-34952
7.8 HIGH

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34951
3.3 LOW

Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

May 7, 2024
CVE-2021-34950
7.8 HIGH

Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34949
5.5 MEDIUM

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34948
7.8 HIGH

Foxit PDF Reader Square Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34947
8.8 HIGH

NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. …

May 7, 2024
CVE-2024-23551
6.5 MEDIUM

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a …

May 7, 2024
CVE-2024-4030
7.1 HIGH

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, …

May 7, 2024
CVE-2024-34346
8.4 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged …

May 7, 2024
CVE-2024-27273
8.1 HIGH

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with …

May 7, 2024
CVE-2024-23713
7.8 HIGH

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of …

May 7, 2024
CVE-2024-23712
5.5 MEDIUM

In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local …

May 7, 2024
CVE-2024-23710
7.8 HIGH

In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. …

May 7, 2024
CVE-2024-23709
6.5 MEDIUM

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with …

May 7, 2024
CVE-2024-23708
7.8 HIGH

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could …

May 7, 2024
CVE-2024-23707
7.8 HIGH

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional …

May 7, 2024
CVE-2024-23706
7.8 HIGH

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of …

May 7, 2024
CVE-2024-23705
7.8 HIGH

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation …

May 7, 2024
CVE-2024-23704
7.8 HIGH

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local …

May 7, 2024
CVE-2024-0043
7.8 HIGH

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the …

May 7, 2024
CVE-2024-0042
7.8 HIGH

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass …

May 7, 2024
CVE-2024-0027
5.5 MEDIUM

In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial …

May 7, 2024
CVE-2024-0026
5.5 MEDIUM

In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service …

May 7, 2024
CVE-2024-0025
7.8 HIGH

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with …

May 7, 2024
CVE-2024-0024
7.8 HIGH

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to …

May 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.