CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30416
7.5 HIGH

Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2023-52717
5.3 MEDIUM

Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2023-52716
7.5 HIGH

Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2023-52715
7.5 HIGH

The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2024
CVE-2023-52714
7.5 HIGH

Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2024
CVE-2023-52713
7.7 HIGH

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Apr 7, 2024
CVE-2023-52382

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 7, 2024
CVE-2021-4438
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function …

Apr 7, 2024
CVE-2024-30415
9.1 CRITICAL

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2024-30414
7.5 HIGH

Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2024
CVE-2024-30413
7.5 HIGH

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2024-3417
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Courseware 1.0. This issue affects some unknown processing of the file admin/saveeditt.php. …

Apr 7, 2024
CVE-2024-3416
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. This vulnerability affects unknown code of the file admin/editt.php. The manipulation of the …

Apr 7, 2024
CVE-2023-6877
6.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Apr 7, 2024
CVE-2024-3415
3.5 LOW

A vulnerability was found in SourceCodester Human Resource Information System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Apr 6, 2024
CVE-2024-3414
3.5 LOW

A vulnerability was found in SourceCodester Human Resource Information System 1.0 and classified as problematic. This issue affects some unknown processing of the file Superadmin_Dashboard/process/addcorporate_process.php. …

Apr 6, 2024
CVE-2024-3413
7.3 HIGH

A vulnerability has been found in SourceCodester Human Resource Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file initialize/login_process.php. …

Apr 6, 2024
CVE-2024-28741
8.8 HIGH

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

Apr 6, 2024
CVE-2024-27620
7.5 HIGH

An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

Apr 6, 2024
CVE-2024-0406
6.1 MEDIUM

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow …

Apr 6, 2024
CVE-2024-3159
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML …

Apr 6, 2024
CVE-2024-3158
8.8 HIGH

Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 6, 2024
CVE-2024-3156
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Apr 6, 2024
CVE-2024-3378
4.3 MEDIUM

A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality …

Apr 6, 2024
CVE-2024-3377
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation …

Apr 6, 2024
CVE-2024-3376
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file config.php. The …

Apr 6, 2024
CVE-2024-25029
9.0 CRITICAL

IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability …

Apr 6, 2024
CVE-2024-24746
7.5 HIGH

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial …

Apr 6, 2024
CVE-2024-22328
7.5 HIGH

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

Apr 6, 2024
CVE-2024-3369
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionality of the …

Apr 6, 2024
CVE-2024-3366
3.5 LOW

A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the …

Apr 6, 2024
CVE-2024-3365
3.5 LOW

A vulnerability was found in SourceCodester Online Library System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Apr 6, 2024
CVE-2024-3364
3.5 LOW

A vulnerability was found in SourceCodester Online Library System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/books/index.php. …

Apr 6, 2024
CVE-2024-3363
7.3 HIGH

A vulnerability was found in SourceCodester Online Library System 1.0. It has been classified as critical. This affects an unknown part of the file admin/borrowed/index.php. …

Apr 6, 2024
CVE-2024-2296
5.5 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions …

Apr 6, 2024
CVE-2024-2132
6.4 MEDIUM

The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and …

Apr 6, 2024
CVE-2024-2458
6.4 MEDIUM

The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, …

Apr 6, 2024
CVE-2024-1428
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to …

Apr 6, 2024
CVE-2024-0837
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to …

Apr 6, 2024
CVE-2024-3362
7.3 HIGH

A vulnerability was found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Apr 6, 2024
CVE-2024-2949
6.4 MEDIUM

The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce …

Apr 6, 2024
CVE-2024-3361
7.3 HIGH

A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Apr 6, 2024
CVE-2024-2471
6.4 MEDIUM

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and …

Apr 6, 2024
CVE-2024-3360
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Online Library System 1.0. Affected is an unknown function of the file admin/books/index.php. The …

Apr 6, 2024
CVE-2024-2444
4.8 MEDIUM

The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 6, 2024
CVE-2024-21506

Rejected reason: Duplicate of CVE-2024-5629.

Apr 6, 2024
CVE-2024-3359
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file …

Apr 6, 2024
CVE-2024-3358
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This vulnerability affects unknown code of the file /index.php. …

Apr 6, 2024
CVE-2024-3216
5.3 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Apr 6, 2024
CVE-2024-2950
5.3 MEDIUM

The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 …

Apr 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.