CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40530
7.5 HIGH

A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.

Aug 5, 2024
CVE-2024-21980
7.9 HIGH

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss …

Aug 5, 2024
CVE-2024-33034
8.4 HIGH

Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at …

Aug 5, 2024
CVE-2024-33028
8.4 HIGH

Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.

Aug 5, 2024
CVE-2024-33027
8.4 HIGH

Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

Aug 5, 2024
CVE-2024-33026
7.5 HIGH

Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.

Aug 5, 2024
CVE-2024-33025
7.5 HIGH

Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

Aug 5, 2024
CVE-2024-33024
7.5 HIGH

Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE …

Aug 5, 2024
CVE-2024-33023
8.4 HIGH

Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.

Aug 5, 2024
CVE-2024-33022
8.4 HIGH

Memory corruption while allocating memory in HGSL driver.

Aug 5, 2024
CVE-2024-33021
8.4 HIGH

Memory corruption while processing IOCTL call to set metainfo.

Aug 5, 2024
CVE-2024-33020
7.5 HIGH

Transient DOS while processing TID-to-link mapping IE elements.

Aug 5, 2024
CVE-2024-33019
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping action frame.

Aug 5, 2024
CVE-2024-33018
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.

Aug 5, 2024
CVE-2024-33015
7.5 HIGH

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less …

Aug 5, 2024
CVE-2024-33014
7.5 HIGH

Transient DOS while parsing ESP IE from beacon/probe response frame.

Aug 5, 2024
CVE-2024-33013
7.5 HIGH

Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.

Aug 5, 2024
CVE-2024-33012
7.5 HIGH

Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.

Aug 5, 2024
CVE-2024-33011
7.5 HIGH

Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

Aug 5, 2024
CVE-2024-33010
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Aug 5, 2024
CVE-2024-23384
8.4 HIGH

Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.

Aug 5, 2024
CVE-2024-23383
8.4 HIGH

Memory corruption when kernel driver attempts to trigger hardware fences.

Aug 5, 2024
CVE-2024-23382
8.4 HIGH

Memory corruption while processing graphics kernel driver request to create DMA fence.

Aug 5, 2024
CVE-2024-23381
8.4 HIGH

Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.

Aug 5, 2024
CVE-2024-23356
7.8 HIGH

Memory corruption during session sign renewal request calls in HLOS.

Aug 5, 2024
CVE-2024-23355
7.8 HIGH

Memory corruption when keymaster operation imports a shared key.

Aug 5, 2024
CVE-2024-23353
7.5 HIGH

Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

Aug 5, 2024
CVE-2024-23352
7.5 HIGH

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

Aug 5, 2024
CVE-2024-21481
8.4 HIGH

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

Aug 5, 2024
CVE-2024-21479
7.5 HIGH

Transient DOS during music playback of ALAC content.

Aug 5, 2024
CVE-2024-7409
7.5 HIGH

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when …

Aug 5, 2024
CVE-2024-7383
7.4 HIGH

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD …

Aug 5, 2024
CVE-2024-6472
7.8 HIGH

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. …

Aug 5, 2024
CVE-2024-4607
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Aug 5, 2024
CVE-2024-2937
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Aug 5, 2024
CVE-2024-36448
7.3 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project …

Aug 5, 2024
CVE-2024-2232
8.1 HIGH

The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

Aug 5, 2024
CVE-2024-6117
8.8 HIGH

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform …

Aug 5, 2024
CVE-2024-41720
8.0 HIGH

Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the …

Aug 5, 2024
CVE-2024-39838
8.8 HIGH

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the …

Aug 5, 2024
CVE-2024-39713
8.6 HIGH

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

Aug 5, 2024
CVE-2024-7465
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Aug 5, 2024
CVE-2024-7463
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7462
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7461
7.3 HIGH

A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 5, 2024
CVE-2024-7449
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file login.php. The …

Aug 4, 2024
CVE-2024-6331
7.5 HIGH

stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with …

Aug 4, 2024
CVE-2024-7444
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php …

Aug 3, 2024
CVE-2024-7441
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read …

Aug 3, 2024
CVE-2024-7439
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read …

Aug 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.