CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29948
3.8 LOW

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable …

Apr 2, 2024
CVE-2024-29947
2.7 LOW

There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may …

Apr 2, 2024
CVE-2023-6951
6.6 MEDIUM

A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the …

Apr 2, 2024
CVE-2023-6950
3.0 LOW

An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious …

Apr 2, 2024
CVE-2023-6949
5.2 MEDIUM

A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 could …

Apr 2, 2024
CVE-2023-6948
3.0 LOW

A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could …

Apr 2, 2024
CVE-2023-51456
6.8 MEDIUM

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2023-51455
6.8 MEDIUM

A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an …

Apr 2, 2024
CVE-2023-51454
6.8 MEDIUM

A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite …

Apr 2, 2024
CVE-2023-51453
3.0 LOW

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2023-51452
3.0 LOW

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2024-2745
3.3 LOW

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when …

Apr 2, 2024
CVE-2024-1946
6.4 MEDIUM

The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 3.1.2 due …

Apr 2, 2024
CVE-2024-1807
6.5 MEDIUM

The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Apr 2, 2024
CVE-2024-1732
5.3 MEDIUM

The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Apr 2, 2024
CVE-2024-2931
4.3 MEDIUM

The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete …

Apr 2, 2024
CVE-2024-31005
8.1 HIGH

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

Apr 2, 2024
CVE-2024-31004
9.8 CRITICAL

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

Apr 2, 2024
CVE-2024-31003
8.8 HIGH

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

Apr 2, 2024
CVE-2024-31002
9.8 CRITICAL

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

Apr 2, 2024
CVE-2024-20799
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Apr 2, 2024
CVE-2024-1300
5.4 MEDIUM

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI …

Apr 2, 2024
CVE-2024-2925
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in all versions up …

Apr 2, 2024
CVE-2024-2839
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_post_title' shortcode in all versions up to, and including, …

Apr 2, 2024
CVE-2024-29276
9.8 CRITICAL

An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.

Apr 2, 2024
CVE-2024-29086
3.3 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

Apr 2, 2024
CVE-2024-29074
6.5 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.

Apr 2, 2024
CVE-2024-28951
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

Apr 2, 2024
CVE-2024-28226
8.1 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

Apr 2, 2024
CVE-2024-26684
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: xgmac: fix handling of DPP safety error for DMA channels Commit 56e58d6c8a56 ("net: …

Apr 2, 2024
CVE-2024-26683
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: detect stuck ECSA element in probe resp We recently added some validation that …

Apr 2, 2024
CVE-2024-26682
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: improve CSA/ECSA connection refusal As mentioned in the previous commit, we pretty quickly …

Apr 2, 2024
CVE-2024-26681
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netdevsim: avoid potential loop in nsim_dev_trap_report_work() Many syzbot reports include the following trace [1] If …

Apr 2, 2024
CVE-2024-26680
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: atlantic: Fix DMA mapping for PTP hwts ring Function aq_ring_hwts_rx_alloc() maps extra AQ_CFG_RXDS_DEF bytes …

Apr 2, 2024
CVE-2024-26679
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: inet: read sk->sk_family once in inet_recv_error() inet_recv_error() is called without holding the socket lock. IPv6 …

Apr 2, 2024
CVE-2024-26678
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section The .compat section is a dummy …

Apr 2, 2024
CVE-2024-26677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix delayed ACKs to not set the reference serial number Fix the construction of …

Apr 2, 2024
CVE-2024-26676
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Call kfree_skb() for dead unix_(sk)->oob_skb in GC. syzbot reported a warning [0] in __unix_gc() …

Apr 2, 2024
CVE-2024-26675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ppp_async: limit MRU to 64K syzbot triggered a warning [1] in __alloc_pages(): WARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, …

Apr 2, 2024
CVE-2024-26674
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups During memory error injection test on kernels >= …

Apr 2, 2024
CVE-2024-26673
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - Disallow families …

Apr 2, 2024
CVE-2024-26672
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c:377 amdgpu_mca_smu_get_mca_entry() …

Apr 2, 2024
CVE-2024-26671
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix IO hang from sbitmap wakeup race In blk_mq_mark_tag_wait(), __add_wait_queue() may be re-ordered with …

Apr 2, 2024
CVE-2024-26670
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD Currently the ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround isn't quite right, as it is supposed …

Apr 2, 2024
CVE-2024-26669
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: Fix chain template offload When a qdisc is deleted from a net device …

Apr 2, 2024
CVE-2024-26668
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: reject configurations that cause integer overflow Reject bogus configs where internal token counter …

Apr 2, 2024
CVE-2024-26667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: check for valid hw_pp in dpu_encoder_helper_phys_cleanup The commit 8b45a26f2ba9 ("drm/msm/dpu: reserve cdm blocks for …

Apr 2, 2024
CVE-2024-26666
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix RCU use in TDLS fast-xmit This looks up the link under RCU …

Apr 2, 2024
CVE-2024-26665
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error …

Apr 2, 2024
CVE-2024-26664
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds …

Apr 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.