CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2656
4.4 MEDIUM

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 6, 2024
CVE-2024-1385
7.1 HIGH

The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() …

Apr 6, 2024
CVE-2024-3245
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Apr 6, 2024
CVE-2024-1994
4.3 MEDIUM

The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all …

Apr 6, 2024
CVE-2024-3357
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the file …

Apr 5, 2024
CVE-2024-3356
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been rated as critical. Affected by this issue is some …

Apr 5, 2024
CVE-2024-3355
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an …

Apr 5, 2024
CVE-2024-30977
7.8 HIGH

An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.

Apr 5, 2024
CVE-2024-27912
7.5 HIGH

A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted …

Apr 5, 2024
CVE-2024-27911
7.5 HIGH

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

Apr 5, 2024
CVE-2024-27910
5.3 MEDIUM

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

Apr 5, 2024
CVE-2024-27909
4.9 MEDIUM

A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.

Apr 5, 2024
CVE-2024-27908
4.9 MEDIUM

A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

Apr 5, 2024
CVE-2024-23592
6.3 MEDIUM

An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and …

Apr 5, 2024
CVE-2023-5912
6.7 MEDIUM

A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM …

Apr 5, 2024
CVE-2023-4605
6.5 MEDIUM

A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

Apr 5, 2024
CVE-2023-25494
6.7 MEDIUM

A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges …

Apr 5, 2024
CVE-2023-25493
6.7 MEDIUM

A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a …

Apr 5, 2024
CVE-2024-3354
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been classified as critical. Affected is an unknown function of …

Apr 5, 2024
CVE-2024-3353
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the …

Apr 5, 2024
CVE-2024-2312
6.7 MEDIUM

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead …

Apr 5, 2024
CVE-2024-29783
6.7 MEDIUM

In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29782
5.5 MEDIUM

In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29757
7.3 HIGH

there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges …

Apr 5, 2024
CVE-2024-29756
9.8 CRITICAL

In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege …

Apr 5, 2024
CVE-2024-29755
4.4 MEDIUM

In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with …

Apr 5, 2024
CVE-2024-29754
6.2 MEDIUM

In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29753
7.7 HIGH

In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29752
7.8 HIGH

In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29751
5.5 MEDIUM

In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29750
5.5 MEDIUM

In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29749
8.4 HIGH

In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29748
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Apr 5, 2024
CVE-2024-29747
5.9 MEDIUM

In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29746
8.4 HIGH

In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Apr 5, 2024
CVE-2024-29745
5.5 MEDIUM KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction …

Apr 5, 2024
CVE-2024-29744
5.5 MEDIUM

In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29743
7.7 HIGH

In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29742
5.5 MEDIUM

In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29741
7.8 HIGH

In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29740
7.4 HIGH

In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29739
5.5 MEDIUM

In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29738
5.5 MEDIUM

In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-27232
5.5 MEDIUM

In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-27231
5.9 MEDIUM

In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-3352
7.3 HIGH

A vulnerability has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Apr 5, 2024
CVE-2024-0081
8.6 HIGH

NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful …

Apr 5, 2024
CVE-2024-3351
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the …

Apr 5, 2024
CVE-2024-3350
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this issue is some …

Apr 5, 2024
CVE-2024-31851
8.6 HIGH

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an …

Apr 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.