CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45596
5.3 MEDIUM

A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. …

Mar 5, 2024
CVE-2023-45595
5.9 MEDIUM

A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to upload …

Mar 5, 2024
CVE-2023-45594
6.8 MEDIUM

A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/from the …

Mar 5, 2024
CVE-2023-45593
6.8 MEDIUM

A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows …

Mar 5, 2024
CVE-2023-45592
6.8 MEDIUM

A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root …

Mar 5, 2024
CVE-2023-45591
7.5 HIGH

A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in …

Mar 5, 2024
CVE-2022-48630
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced …

Mar 5, 2024
CVE-2022-48629
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct …

Mar 5, 2024
CVE-2023-5456
8.1 HIGH

A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service …

Mar 5, 2024
CVE-2024-26339
9.1 CRITICAL

swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

Mar 5, 2024
CVE-2024-26337
4.3 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.

Mar 5, 2024
CVE-2024-26335
5.5 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

Mar 5, 2024
CVE-2024-26334
6.2 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib/action/actioncompiler.c.

Mar 5, 2024
CVE-2024-26333
5.5 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.

Mar 5, 2024
CVE-2024-20833
4.1 MEDIUM

Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory …

Mar 5, 2024
CVE-2023-42419
3.8 LOW

Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative …

Mar 5, 2024
CVE-2024-20841
5.1 MEDIUM

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

Mar 5, 2024
CVE-2024-20840
5.7 MEDIUM

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using …

Mar 5, 2024
CVE-2024-20839
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to …

Mar 5, 2024
CVE-2024-20838
6.8 MEDIUM

Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20837
5.3 MEDIUM

Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own …

Mar 5, 2024
CVE-2024-20836
3.3 LOW

Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

Mar 5, 2024
CVE-2024-20835
4.0 MEDIUM

Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.

Mar 5, 2024
CVE-2024-20834
3.3 LOW

The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.

Mar 5, 2024
CVE-2024-20832
6.4 MEDIUM

Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20831
6.4 MEDIUM

Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20830
5.3 MEDIUM

Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

Mar 5, 2024
CVE-2024-20829
5.4 MEDIUM

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

Mar 5, 2024
CVE-2023-52432
5.9 MEDIUM

Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.

Mar 5, 2024
CVE-2024-22383
6.2 MEDIUM

Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under …

Mar 5, 2024
CVE-2024-21838
6.8 MEDIUM

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection …

Mar 5, 2024
CVE-2024-21815
9.1 CRITICAL

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher …

Mar 5, 2024
CVE-2024-22188
7.2 HIGH

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via …

Mar 5, 2024
CVE-2024-1782
6.1 MEDIUM

The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' parameter in all versions up to, and including, 1.0 …

Mar 5, 2024
CVE-2024-1769
5.3 MEDIUM

The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description data. …

Mar 5, 2024
CVE-2024-1731
8.8 HIGH

The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of …

Mar 5, 2024
CVE-2024-1478
5.3 MEDIUM

The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This …

Mar 5, 2024
CVE-2024-1381
6.5 MEDIUM

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Mar 5, 2024
CVE-2024-1285
6.5 MEDIUM

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Mar 5, 2024
CVE-2024-1178
5.3 MEDIUM

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 5, 2024
CVE-2024-1095
5.3 MEDIUM

The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Mar 5, 2024
CVE-2024-1093
5.3 MEDIUM

The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic() function hooked …

Mar 5, 2024
CVE-2024-1088
5.3 MEDIUM

The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the …

Mar 5, 2024
CVE-2024-0825
8.8 HIGH

The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via …

Mar 5, 2024
CVE-2024-0698
6.4 MEDIUM

The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due …

Mar 5, 2024
CVE-2024-25269
7.5 HIGH

libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

Mar 5, 2024
CVE-2024-27718
7.8 HIGH

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php …

Mar 5, 2024
CVE-2024-25731
7.5 HIGH

The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can …

Mar 5, 2024
CVE-2024-25164
7.5 HIGH

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

Mar 5, 2024
CVE-2023-49970
9.8 CRITICAL

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.