CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0684
5.5 MEDIUM

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in …

Feb 6, 2024
CVE-2023-4503
6.8 MEDIUM

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue …

Feb 6, 2024
CVE-2024-22365
5.5 MEDIUM

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) …

Feb 6, 2024
CVE-2023-32479
6.7 MEDIUM

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of …

Feb 6, 2024
CVE-2023-32474
6.6 MEDIUM

Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability …

Feb 6, 2024
CVE-2023-32454
6.3 MEDIUM

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create …

Feb 6, 2024
CVE-2023-32451
7.3 HIGH

Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation

Feb 6, 2024
CVE-2023-28063
6.7 MEDIUM

Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to …

Feb 6, 2024
CVE-2024-22433
8.8 HIGH

Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated …

Feb 6, 2024
CVE-2023-52239
6.5 MEDIUM

The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.

Feb 6, 2024
CVE-2023-28049
4.7 MEDIUM

Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order …

Feb 6, 2024
CVE-2023-25543
7.8 HIGH

Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability …

Feb 6, 2024
CVE-2023-43536
7.5 HIGH

Transient DOS while parse fils IE with length equal to 1.

Feb 6, 2024
CVE-2023-43535
8.4 HIGH

Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.

Feb 6, 2024
CVE-2023-43534
8.6 HIGH

Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.

Feb 6, 2024
CVE-2023-43533
7.5 HIGH

Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.

Feb 6, 2024
CVE-2023-43532
8.4 HIGH

Memory corruption while reading ACPI config through the user mode app.

Feb 6, 2024
CVE-2023-43523
7.5 HIGH

Transient DOS while processing 11AZ RTT management action frame received through OTA.

Feb 6, 2024
CVE-2023-43522
7.5 HIGH

Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

Feb 6, 2024
CVE-2023-43520
8.6 HIGH

Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.

Feb 6, 2024
CVE-2023-43519
7.3 HIGH

Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.

Feb 6, 2024
CVE-2023-43518
7.3 HIGH

Memory corruption in video while parsing invalid mp2 clip.

Feb 6, 2024
CVE-2023-43517
8.4 HIGH

Memory corruption in Automotive Multimedia due to improper access control in HAB.

Feb 6, 2024
CVE-2023-43516
7.8 HIGH

Memory corruption when malformed message payload is received from firmware.

Feb 6, 2024
CVE-2023-43513
7.8 HIGH

Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point …

Feb 6, 2024
CVE-2023-33077
6.7 MEDIUM

Memory corruption in HLOS while converting from authorization token to HIDL vector.

Feb 6, 2024
CVE-2023-33076
5.9 MEDIUM

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

Feb 6, 2024
CVE-2023-33072
9.3 CRITICAL

Memory corruption in Core while processing control functions.

Feb 6, 2024
CVE-2023-33069
6.7 MEDIUM

Memory corruption in Audio while processing the calibration data returned from ACDB loader.

Feb 6, 2024
CVE-2023-33068
6.7 MEDIUM

Memory corruption in Audio while processing IIR config data from AFE calibration block.

Feb 6, 2024
CVE-2023-33067
6.7 MEDIUM

Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.

Feb 6, 2024
CVE-2023-33065
6.1 MEDIUM

Information disclosure in Audio while accessing AVCS services from ADSP payload.

Feb 6, 2024
CVE-2023-33064
5.5 MEDIUM

Transient DOS in Audio when invoking callback function of ASM driver.

Feb 6, 2024
CVE-2023-33060
7.1 HIGH

Transient DOS in Core when DDR memory check is called while DDR is not initialized.

Feb 6, 2024
CVE-2023-33058
8.2 HIGH

Information disclosure in Modem while processing SIB5.

Feb 6, 2024
CVE-2023-33057
7.5 HIGH

Transient DOS in Multi-Mode Call Processor while processing UE policy container.

Feb 6, 2024
CVE-2023-33049
7.5 HIGH

Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

Feb 6, 2024
CVE-2023-33046
7.8 HIGH

Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

Feb 6, 2024
CVE-2024-23304
7.5 HIGH

Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

Feb 6, 2024
CVE-2024-24808
4.7 MEDIUM

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting …

Feb 6, 2024
CVE-2024-20828
2.4 LOW

Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.

Feb 6, 2024
CVE-2024-20827
4.6 MEDIUM

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

Feb 6, 2024
CVE-2024-20826
5.5 MEDIUM

Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20825
5.5 MEDIUM

Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20824
5.5 MEDIUM

Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20823
5.5 MEDIUM

Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20822
5.5 MEDIUM

Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20820
4.4 MEDIUM

Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

Feb 6, 2024
CVE-2024-20819
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20818
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.