CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32982
8.2 HIGH

Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been …

May 6, 2024
CVE-2024-32972
7.5 HIGH

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large …

May 6, 2024
CVE-2024-23354
8.4 HIGH

Memory corruption when the IOCTL call is interrupted by a signal.

May 6, 2024
CVE-2024-23351
8.4 HIGH

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

May 6, 2024
CVE-2024-21480
7.3 HIGH

Memory corruption while playing audio file having large-sized input buffer.

May 6, 2024
CVE-2024-21477
7.5 HIGH

Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.

May 6, 2024
CVE-2024-21476
7.8 HIGH

Memory corruption when the channel ID passed by user is not validated and further used.

May 6, 2024
CVE-2024-21475
7.8 HIGH

Memory corruption when the payload received from firmware is not as per the expected protocol size.

May 6, 2024
CVE-2024-21474
8.4 HIGH

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

May 6, 2024
CVE-2024-21471
8.4 HIGH

Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

May 6, 2024
CVE-2023-43531
8.4 HIGH

Memory corruption while verifying the serialized header when the key pairs are generated.

May 6, 2024
CVE-2023-43530
5.9 MEDIUM

Memory corruption in HLOS while checking for the storage type.

May 6, 2024
CVE-2023-43529
7.5 HIGH

Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.

May 6, 2024
CVE-2023-43528
6.1 MEDIUM

Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

May 6, 2024
CVE-2023-43527
6.8 MEDIUM

Information disclosure while parsing dts header atom in Video.

May 6, 2024
CVE-2023-43526
6.7 MEDIUM

Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

May 6, 2024
CVE-2023-43525
6.7 MEDIUM

Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

May 6, 2024
CVE-2023-43524
6.7 MEDIUM

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

May 6, 2024
CVE-2023-43521
6.7 MEDIUM

Memory corruption when multiple listeners are being registered with the same file descriptor.

May 6, 2024
CVE-2023-33119
8.4 HIGH

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

May 6, 2024
CVE-2024-4549
7.5 HIGH

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

May 6, 2024
CVE-2024-4548
9.8 CRITICAL

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the …

May 6, 2024
CVE-2024-4547
9.8 CRITICAL

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the …

May 6, 2024
CVE-2024-33752
6.3 MEDIUM

An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit …

May 6, 2024
CVE-2024-2041

Rejected reason: ***DUPLICATE** Please use CVE-2024-3241 instead.

May 6, 2024
CVE-2024-33830
8.1 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

May 6, 2024
CVE-2024-33829
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

May 6, 2024
CVE-2024-33788
8.0 HIGH

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

May 6, 2024
CVE-2024-33749
9.1 CRITICAL

DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

May 6, 2024
CVE-2024-3576
8.3 HIGH

The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing …

May 6, 2024
CVE-2024-33753
8.2 HIGH

Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.

May 6, 2024
CVE-2023-49676
5.5 MEDIUM

An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

May 6, 2024
CVE-2023-49675
7.8 HIGH

An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds …

May 6, 2024
CVE-2023-6854
6.4 MEDIUM

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 …

May 6, 2024
CVE-2024-4528
2.4 LOW

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

May 6, 2024
CVE-2024-23193
5.3 MEDIUM

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same …

May 6, 2024
CVE-2024-23188
6.5 MEDIUM

Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is …

May 6, 2024
CVE-2024-23187
6.5 MEDIUM

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious …

May 6, 2024
CVE-2024-23186
6.5 MEDIUM

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from …

May 6, 2024
CVE-2024-4527
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the …

May 6, 2024
CVE-2024-4526
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file …

May 6, 2024
CVE-2024-4525
3.5 LOW

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file …

May 6, 2024
CVE-2024-4524
3.5 LOW

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file …

May 6, 2024
CVE-2024-3756
7.5 HIGH

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors …

May 6, 2024
CVE-2024-3755
5.4 MEDIUM

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-3752
5.4 MEDIUM

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 6, 2024
CVE-2024-0904
5.9 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-4523
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown …

May 6, 2024
CVE-2024-4522
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

May 6, 2024
CVE-2024-4521
3.5 LOW

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_details2.php. …

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.