CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33060
8.4 HIGH

Memory corruption when two threads try to map and unmap a single node simultaneously.

Sep 2, 2024
CVE-2024-33057
7.5 HIGH

Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.

Sep 2, 2024
CVE-2024-33054
7.8 HIGH

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

Sep 2, 2024
CVE-2024-33052
7.8 HIGH

Memory corruption when user provides data for FM HCI command control operations.

Sep 2, 2024
CVE-2024-33051
7.5 HIGH

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

Sep 2, 2024
CVE-2024-33050
7.5 HIGH

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

Sep 2, 2024
CVE-2024-33048
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

Sep 2, 2024
CVE-2024-33047
8.4 HIGH

Memory corruption when the captureRead QDCM command is invoked from user-space.

Sep 2, 2024
CVE-2024-33045
8.4 HIGH

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Sep 2, 2024
CVE-2024-33042
7.8 HIGH

Memory corruption when Alternative Frequency offset value is set to 255.

Sep 2, 2024
CVE-2024-33038
7.8 HIGH

Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

Sep 2, 2024
CVE-2024-33035
8.4 HIGH

Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

Sep 2, 2024
CVE-2024-23365
8.4 HIGH

Memory corruption while releasing shared resources in MinkSocket listener thread.

Sep 2, 2024
CVE-2024-23364
7.5 HIGH

Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air …

Sep 2, 2024
CVE-2024-23362
7.1 HIGH

Cryptographic issue while parsing RSA keys in COBR format.

Sep 2, 2024
CVE-2024-23359
8.2 HIGH

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

Sep 2, 2024
CVE-2024-23358
7.5 HIGH

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

Sep 2, 2024
CVE-2024-7871
8.8 HIGH

SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43776
8.8 HIGH

SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43775
8.8 HIGH

SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via …

Sep 2, 2024
CVE-2024-43774
8.8 HIGH

SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands …

Sep 2, 2024
CVE-2024-41160
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-41157
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-39816
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024
CVE-2024-38386
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024
CVE-2024-20089
7.5 HIGH

In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional …

Sep 2, 2024
CVE-2024-8368
7.3 HIGH

A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 1, 2024
CVE-2024-7717
8.8 HIGH

The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 …

Aug 31, 2024
CVE-2024-44945
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN …

Aug 31, 2024
CVE-2024-7435
8.8 HIGH

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This …

Aug 31, 2024
CVE-2024-39747
8.1 HIGH

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Aug 31, 2024
CVE-2024-6586
7.3 HIGH

Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements …

Aug 30, 2024
CVE-2024-38868
7.6 HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15

Aug 30, 2024
CVE-2024-6204
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

Aug 30, 2024
CVE-2024-8343
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file …

Aug 30, 2024
CVE-2024-44916
7.2 HIGH

Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in …

Aug 30, 2024
CVE-2024-8340
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The …

Aug 30, 2024
CVE-2024-8252
8.8 HIGH

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of …

Aug 30, 2024
CVE-2024-2694
8.8 HIGH

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of …

Aug 30, 2024
CVE-2024-5784
7.1 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete …

Aug 30, 2024
CVE-2024-8330
8.8 HIGH

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use …

Aug 30, 2024
CVE-2024-8329
8.8 HIGH

6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, …

Aug 30, 2024
CVE-2024-8327
8.8 HIGH

Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular …

Aug 30, 2024
CVE-2024-45490
7.5 HIGH

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

Aug 30, 2024
CVE-2024-8234
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow …

Aug 30, 2024
CVE-2024-6672
8.8 HIGH

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's …

Aug 29, 2024
CVE-2024-34019
7.3 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

Aug 29, 2024
CVE-2024-34017
7.3 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

Aug 29, 2024
CVE-2024-43921
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: …

Aug 29, 2024
CVE-2024-43963
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.This issue affects …

Aug 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.