CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13495
7.3 HIGH

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via …

Jan 22, 2025
CVE-2025-0429
7.2 HIGH

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of …

Jan 22, 2025
CVE-2025-0428
7.2 HIGH

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of …

Jan 22, 2025
CVE-2025-22450
7.5 HIGH

Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected products, …

Jan 22, 2025
CVE-2025-20617
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If an attacker logs …

Jan 22, 2025
CVE-2024-11218
8.6 HIGH

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building …

Jan 22, 2025
CVE-2025-23083
7.7 HIGH

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to …

Jan 22, 2025
CVE-2024-49749
8.8 HIGH

In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with …

Jan 21, 2025
CVE-2024-49745
7.8 HIGH

In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jan 21, 2025
CVE-2024-49744
7.8 HIGH

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of …

Jan 21, 2025
CVE-2024-49742
7.8 HIGH

In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. …

Jan 21, 2025
CVE-2024-49738
7.8 HIGH

In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges …

Jan 21, 2025
CVE-2024-49737
7.8 HIGH

In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. …

Jan 21, 2025
CVE-2024-49735
7.8 HIGH

In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with …

Jan 21, 2025
CVE-2024-49734
7.5 HIGH

In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a …

Jan 21, 2025
CVE-2024-49732
7.8 HIGH

In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead …

Jan 21, 2025
CVE-2024-49724
7.0 HIGH

In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead …

Jan 21, 2025
CVE-2024-43771
8.8 HIGH

In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code …

Jan 21, 2025
CVE-2024-43770
8.8 HIGH

In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code …

Jan 21, 2025
CVE-2024-43765
7.8 HIGH

In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation …

Jan 21, 2025
CVE-2024-43096
8.8 HIGH

In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code …

Jan 21, 2025
CVE-2024-43095
7.8 HIGH

In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This could lead to …

Jan 21, 2025
CVE-2024-34730
7.8 HIGH

In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This …

Jan 21, 2025
CVE-2024-24428
7.5 HIGH

A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

Jan 21, 2025
CVE-2024-24427
7.5 HIGH

A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

Jan 21, 2025
CVE-2024-24424
7.5 HIGH

A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) …

Jan 21, 2025
CVE-2024-24423
7.5 HIGH

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container function at /nas/ies/EsmMessageContainer.cpp. This …

Jan 21, 2025
CVE-2024-24422
7.5 HIGH

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This …

Jan 21, 2025
CVE-2024-24420
7.5 HIGH

A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) …

Jan 21, 2025
CVE-2024-24419
7.5 HIGH

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This …

Jan 21, 2025
CVE-2024-24418
7.5 HIGH

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp. This …

Jan 21, 2025
CVE-2024-24417
7.5 HIGH

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This …

Jan 21, 2025
CVE-2024-24416
7.5 HIGH

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This …

Jan 21, 2025
CVE-2023-40132
7.8 HIGH

In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to …

Jan 21, 2025
CVE-2023-37032
7.5 HIGH

A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash …

Jan 21, 2025
CVE-2023-37029
7.5 HIGH

Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may …

Jan 21, 2025
CVE-2023-37024
7.5 HIGH

A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the …

Jan 21, 2025
CVE-2025-23196
8.8 HIGH

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when …

Jan 21, 2025
CVE-2025-23195
7.5 HIGH

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure …

Jan 21, 2025
CVE-2024-51941
8.8 HIGH

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability …

Jan 21, 2025
CVE-2024-24451
7.5 HIGH

A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by …

Jan 21, 2025
CVE-2024-24444
7.5 HIGH

Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by …

Jan 21, 2025
CVE-2024-24442
7.5 HIGH

A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) …

Jan 21, 2025
CVE-2023-50733
8.6 HIGH

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.

Jan 21, 2025
CVE-2025-21571
7.3 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6. …

Jan 21, 2025
CVE-2025-21565
7.5 HIGH

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability …

Jan 21, 2025
CVE-2025-21564
8.1 HIGH

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily …

Jan 21, 2025
CVE-2025-21549
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows …

Jan 21, 2025
CVE-2025-21545
7.5 HIGH

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows …

Jan 21, 2025
CVE-2025-21532
7.8 HIGH

Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows …

Jan 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.