CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45553
7.8 HIGH

Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread …

Jan 6, 2025
CVE-2024-45550
7.8 HIGH

Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.

Jan 6, 2025
CVE-2024-45548
7.8 HIGH

Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.

Jan 6, 2025
CVE-2024-45547
7.8 HIGH

Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.

Jan 6, 2025
CVE-2024-45546
7.8 HIGH

Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.

Jan 6, 2025
CVE-2024-45542
7.8 HIGH

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

Jan 6, 2025
CVE-2024-45541
7.8 HIGH

Memory corruption when IOCTL call is invoked from user-space to read board data.

Jan 6, 2025
CVE-2024-43064
7.5 HIGH

Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.

Jan 6, 2025
CVE-2024-21464
8.4 HIGH

Memory corruption while processing IPA statistics, when there are no active clients registered.

Jan 6, 2025
CVE-2024-20154
8.8 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a …

Jan 6, 2025
CVE-2024-20153
7.5 HIGH

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote …

Jan 6, 2025
CVE-2024-20150
7.5 HIGH

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution …

Jan 6, 2025
CVE-2024-20149
7.5 HIGH

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Jan 6, 2025
CVE-2024-20146
8.1 HIGH

In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution …

Jan 6, 2025
CVE-2025-0233
7.3 HIGH

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/course.php. …

Jan 5, 2025
CVE-2024-41767
7.3 HIGH

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could …

Jan 4, 2025
CVE-2024-41766
7.5 HIGH

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.

Jan 4, 2025
CVE-2025-0210
7.3 HIGH

A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 4, 2025
CVE-2024-10957
8.8 HIGH

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization …

Jan 4, 2025
CVE-2025-0207
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of …

Jan 4, 2025
CVE-2024-10932
8.8 HIGH

The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input …

Jan 4, 2025
CVE-2025-22390
7.5 HIGH

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The …

Jan 4, 2025
CVE-2025-22389
8.0 HIGH

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. …

Jan 4, 2025
CVE-2025-22387
7.5 HIGH

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as …

Jan 4, 2025
CVE-2025-22386
7.3 HIGH

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active …

Jan 4, 2025
CVE-2025-22384
7.5 HIGH

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront …

Jan 4, 2025
CVE-2024-11733
7.3 HIGH

The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due …

Jan 3, 2025
CVE-2024-13129
8.8 HIGH

A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the …

Jan 3, 2025
CVE-2024-35365
8.8 HIGH

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.

Jan 3, 2025
CVE-2024-56324
7.1 HIGH

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration …

Jan 3, 2025
CVE-2024-56322
7.2 HIGH

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) …

Jan 3, 2025
CVE-2024-56320
8.8 HIGH

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the …

Jan 3, 2025
CVE-2024-48814
7.5 HIGH

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function

Jan 3, 2025
CVE-2024-9138
7.2 HIGH

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user …

Jan 3, 2025
CVE-2024-53841
7.8 HIGH

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution …

Jan 3, 2025
CVE-2024-53840
7.8 HIGH

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges …

Jan 3, 2025
CVE-2024-53838
7.8 HIGH

In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jan 3, 2025
CVE-2024-53837
7.8 HIGH

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-53835
7.8 HIGH

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges …

Jan 3, 2025
CVE-2024-53834
7.5 HIGH

In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure …

Jan 3, 2025
CVE-2024-53833
7.8 HIGH

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-47032
7.8 HIGH

In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Jan 3, 2025
CVE-2024-11624
7.8 HIGH

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no …

Jan 3, 2025
CVE-2024-43769
7.8 HIGH

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. …

Jan 3, 2025
CVE-2024-43768
7.8 HIGH

In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-43767
8.8 HIGH

In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remote code execution with no additional …

Jan 3, 2025
CVE-2024-43764
7.8 HIGH

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional …

Jan 3, 2025
CVE-2024-43762
7.8 HIGH

In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. …

Jan 3, 2025
CVE-2024-43097
7.8 HIGH

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jan 3, 2025
CVE-2024-43077
7.8 HIGH

In DevmemValidateFlags of devicemem_server.c , there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege …

Jan 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.