CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-33057
7.5 HIGH

Transient DOS in Multi-Mode Call Processor while processing UE policy container.

Feb 6, 2024
CVE-2023-33049
7.5 HIGH

Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

Feb 6, 2024
CVE-2023-33046
7.8 HIGH

Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

Feb 6, 2024
CVE-2024-23304
7.5 HIGH

Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

Feb 6, 2024
CVE-2024-24808
4.7 MEDIUM

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting …

Feb 6, 2024
CVE-2024-20828
2.4 LOW

Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.

Feb 6, 2024
CVE-2024-20827
4.6 MEDIUM

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

Feb 6, 2024
CVE-2024-20826
5.5 MEDIUM

Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20825
5.5 MEDIUM

Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20824
5.5 MEDIUM

Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20823
5.5 MEDIUM

Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20822
5.5 MEDIUM

Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20820
4.4 MEDIUM

Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

Feb 6, 2024
CVE-2024-20819
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20818
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20817
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20816
8.0 HIGH

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

Feb 6, 2024
CVE-2024-20815
8.0 HIGH

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

Feb 6, 2024
CVE-2024-20814
4.0 MEDIUM

Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.

Feb 6, 2024
CVE-2024-20813
8.4 HIGH

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Feb 6, 2024
CVE-2024-20812
8.4 HIGH

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Feb 6, 2024
CVE-2024-20811
5.1 MEDIUM

Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.

Feb 6, 2024
CVE-2024-20810
3.3 LOW

Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

Feb 6, 2024
CVE-2024-22853
9.8 CRITICAL

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

Feb 6, 2024
CVE-2024-22852
9.8 CRITICAL

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

Feb 6, 2024
CVE-2024-24112
9.8 CRITICAL

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

Feb 6, 2024
CVE-2024-22773
8.1 HIGH

Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

Feb 6, 2024
CVE-2024-0244
9.8 CRITICAL

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

Feb 6, 2024
CVE-2023-6234
9.8 CRITICAL

Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment …

Feb 6, 2024
CVE-2023-6233
9.8 CRITICAL

Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

Feb 6, 2024
CVE-2023-6232
9.8 CRITICAL

Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an …

Feb 6, 2024
CVE-2023-6231
9.8 CRITICAL

Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

Feb 6, 2024
CVE-2023-6230
9.8 CRITICAL

Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an …

Feb 6, 2024
CVE-2023-6229
9.8 CRITICAL

Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to …

Feb 6, 2024
CVE-2023-47889
7.8 HIGH

The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device …

Feb 6, 2024
CVE-2023-47353
8.8 HIGH

An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.

Feb 6, 2024
CVE-2023-47022
6.5 MEDIUM

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to …

Feb 6, 2024
CVE-2023-46360
8.8 HIGH

Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.

Feb 6, 2024
CVE-2023-46359
9.8 CRITICAL

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on …

Feb 6, 2024
CVE-2024-24398
9.8 CRITICAL

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName …

Feb 6, 2024
CVE-2023-47354
7.8 HIGH

An issue in the PowerOffWidgetReceiver function of Super Reboot (Root) Recovery v1.0.3 allows attackers to arbitrarily reset or power off the device via a crafted …

Feb 6, 2024
CVE-2024-23049
9.8 CRITICAL

An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.

Feb 5, 2024
CVE-2024-0964
9.4 CRITICAL

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

Feb 5, 2024
CVE-2024-24595
6.0 MEDIUM

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

Feb 5, 2024
CVE-2024-1210
5.3 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it …

Feb 5, 2024
CVE-2024-1209
5.3 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due …

Feb 5, 2024
CVE-2024-1208
5.3 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it …

Feb 5, 2024
CVE-2024-1177
5.3 MEDIUM

The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 5, 2024
CVE-2024-1121
5.3 MEDIUM

The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_file() function …

Feb 5, 2024
CVE-2024-1092
4.3 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.