CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52550
7.5 HIGH

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52549
7.5 HIGH

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52546
7.5 HIGH

Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52545
7.5 HIGH

Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52544
4.3 MEDIUM

Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52543
6.2 MEDIUM

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52542
6.5 MEDIUM

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52541
7.5 HIGH

Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52540
7.5 HIGH

Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52539
7.5 HIGH

Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52538
9.1 CRITICAL

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52537
7.5 HIGH

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52388
7.5 HIGH

Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52359
7.5 HIGH

Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2024-30675

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30674

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30672

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30667

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30666

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30665

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30663

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30662

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30661

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-30659

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 8, 2024
CVE-2024-31022
9.8 CRITICAL

An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.

Apr 8, 2024
CVE-2024-27488
9.8 CRITICAL

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the …

Apr 8, 2024
CVE-2024-1958
4.8 MEDIUM

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Apr 8, 2024
CVE-2024-1956
6.1 MEDIUM

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading …

Apr 8, 2024
CVE-2024-1752
6.1 MEDIUM

The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1589
6.1 MEDIUM

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1588
6.8 MEDIUM

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1292
4.7 MEDIUM

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a …

Apr 8, 2024
CVE-2024-23658
4.4 MEDIUM

In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Apr 8, 2024
CVE-2023-52536
4.4 MEDIUM

In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52535
4.4 MEDIUM

In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed

Apr 8, 2024
CVE-2023-52534
5.9 MEDIUM

In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Apr 8, 2024
CVE-2023-52533
5.3 MEDIUM

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52352
5.5 MEDIUM

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

Apr 8, 2024
CVE-2023-52351
7.8 HIGH

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52350
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52349
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52348
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52347
5.5 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52346
4.4 MEDIUM

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges …

Apr 8, 2024
CVE-2023-52345
6.0 MEDIUM

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges …

Apr 8, 2024
CVE-2023-52344
5.3 MEDIUM

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52343
5.5 MEDIUM

In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional …

Apr 8, 2024
CVE-2023-52342
7.5 HIGH

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52341
7.5 HIGH

In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no …

Apr 8, 2024
CVE-2024-28744
8.8 HIGH

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker …

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.