CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27668
6.1 MEDIUM

Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'

Mar 4, 2024
CVE-2024-0686

Rejected reason: Incorrect assignment

Mar 4, 2024
CVE-2024-27684
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML …

Mar 4, 2024
CVE-2024-24901
3.0 LOW

Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit …

Mar 4, 2024
CVE-2024-22463
7.4 HIGH

Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this …

Mar 4, 2024
CVE-2024-22452
7.3 HIGH

Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability …

Mar 4, 2024
CVE-2024-0156
7.0 HIGH

Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary …

Mar 4, 2024
CVE-2024-0155
7.0 HIGH

Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to …

Mar 4, 2024
CVE-2023-6241
7.0 HIGH

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd …

Mar 4, 2024
CVE-2023-43553
9.8 CRITICAL

Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.

Mar 4, 2024
CVE-2023-43552
9.8 CRITICAL

Memory corruption while processing MBSSID beacon containing several subelement IE.

Mar 4, 2024
CVE-2023-43550
7.8 HIGH

Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.

Mar 4, 2024
CVE-2023-43549
8.4 HIGH

Memory corruption while processing TPC target power table in FTM TPC.

Mar 4, 2024
CVE-2023-43548
7.3 HIGH

Memory corruption while parsing qcp clip with invalid chunk data size.

Mar 4, 2024
CVE-2023-43547
8.4 HIGH

Memory corruption while invoking IOCTLs calls in Automotive Multimedia.

Mar 4, 2024
CVE-2023-43546
8.4 HIGH

Memory corruption while invoking HGSL IOCTL context create.

Mar 4, 2024
CVE-2023-43541
8.4 HIGH

Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.

Mar 4, 2024
CVE-2023-43540
8.4 HIGH

Memory corruption while processing the IOCTL FM HCI WRITE request.

Mar 4, 2024
CVE-2023-43539
7.5 HIGH

Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.

Mar 4, 2024
CVE-2023-33105
7.5 HIGH

Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.

Mar 4, 2024
CVE-2023-33104
7.5 HIGH

Transient DOS while processing PDU Release command with a parameter PDU ID out of range.

Mar 4, 2024
CVE-2023-33103
7.5 HIGH

Transient DOS while processing CAG info IE received from NW.

Mar 4, 2024
CVE-2023-33096
7.5 HIGH

Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

Mar 4, 2024
CVE-2023-33095
7.5 HIGH

Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.

Mar 4, 2024
CVE-2023-33090
5.5 MEDIUM

Transient DOS while processing channel information for speaker protection v2 module in ADSP.

Mar 4, 2024
CVE-2023-33086
7.5 HIGH

Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.

Mar 4, 2024
CVE-2023-33084
7.5 HIGH

Transient DOS while processing IE fragments from server during DTLS handshake.

Mar 4, 2024
CVE-2023-33078
5.1 MEDIUM

Information Disclosure while processing IOCTL request in FastRPC.

Mar 4, 2024
CVE-2023-33066
8.4 HIGH

Memory corruption in Audio while processing RT proxy port register driver.

Mar 4, 2024
CVE-2023-28582
9.8 CRITICAL

Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.

Mar 4, 2024
CVE-2023-28578
9.3 CRITICAL

Memory corruption in Core Services while executing the command for removing a single event listener.

Mar 4, 2024
CVE-2023-6143
8.4 HIGH

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd …

Mar 4, 2024
CVE-2023-4479
7.3 HIGH

Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.

Mar 4, 2024
CVE-2024-26622
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control() Since tomoyo_write_control() updates head->write_buf when write() of long …

Mar 4, 2024
CVE-2024-21826
4.3 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

Mar 4, 2024
CVE-2024-21816
4.0 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

Mar 4, 2024
CVE-2023-49602
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

Mar 4, 2024
CVE-2023-46708
4.3 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

Mar 4, 2024
CVE-2023-25176
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Mar 4, 2024
CVE-2024-20038
3.4 LOW

In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System …

Mar 4, 2024
CVE-2024-20037
6.7 MEDIUM

In pq, there is a possible write-what-where condition due to an incorrect bounds check. This could lead to local escalation of privilege with System execution …

Mar 4, 2024
CVE-2024-20036
4.4 MEDIUM

In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. …

Mar 4, 2024
CVE-2024-20034
7.2 HIGH

In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20033
4.4 MEDIUM

In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Mar 4, 2024
CVE-2024-20032
6.7 MEDIUM

In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution …

Mar 4, 2024
CVE-2024-20031
6.7 MEDIUM

In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20030
4.4 MEDIUM

In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. …

Mar 4, 2024
CVE-2024-20029
8.4 HIGH

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Mar 4, 2024
CVE-2024-20028
6.6 MEDIUM

In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20027
7.9 HIGH

In da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System …

Mar 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.