CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32919
7.8 HIGH

In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-32917
7.1 HIGH

In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jun 13, 2024
CVE-2024-32909
7.8 HIGH

In handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Jun 13, 2024
CVE-2024-32908
7.8 HIGH

In sec_media_protect of media.c, there is a possible permission bypass due to a race condition. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-32907
7.8 HIGH

In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-32906
7.8 HIGH

In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution …

Jun 13, 2024
CVE-2024-32903
7.8 HIGH

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-32902
7.5 HIGH

Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)

Jun 13, 2024
CVE-2024-32901
7.8 HIGH

In v4l2_smfc_qbuf of smfc-v4l2-ioctls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jun 13, 2024
CVE-2024-32900
7.8 HIGH

In lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of privilege from hal_camera_default …

Jun 13, 2024
CVE-2024-32899
7.0 HIGH

In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-32896
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-32895
7.8 HIGH

In BCMFASTPATH of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jun 13, 2024
CVE-2024-32894
7.5 HIGH

In bc_get_converted_received_bearer of bc_utilities.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Jun 13, 2024
CVE-2024-32892
7.8 HIGH

In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional …

Jun 13, 2024
CVE-2024-32891
7.0 HIGH

In sec_media_unprotect of media.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-29787
7.8 HIGH

In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-29784
7.8 HIGH

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Jun 13, 2024
CVE-2024-29781
7.5 HIGH

In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with …

Jun 13, 2024
CVE-2024-5950
8.8 HIGH

Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …

Jun 13, 2024
CVE-2024-5948
8.8 HIGH

Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Jun 13, 2024
CVE-2024-5924
8.8 HIGH

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User …

Jun 13, 2024
CVE-2024-4696
7.5 HIGH

A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a …

Jun 13, 2024
CVE-2024-37633
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg

Jun 13, 2024
CVE-2024-37631
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.

Jun 13, 2024
CVE-2024-36587
7.8 HIGH

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

Jun 13, 2024
CVE-2024-36586
8.8 HIGH

An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.

Jun 13, 2024
CVE-2024-37630
8.8 HIGH

D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

Jun 13, 2024
CVE-2024-37029
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 13, 2024
CVE-2024-37022
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipulate memory, resulting in execution of arbitrary code.

Jun 13, 2024
CVE-2024-36760
7.5 HIGH

A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : …

Jun 13, 2024
CVE-2024-32504
8.4 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, …

Jun 13, 2024
CVE-2024-31956
8.4 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an …

Jun 13, 2024
CVE-2024-37307
7.9 HIGH

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the …

Jun 13, 2024
CVE-2024-37306
7.1 HIGH

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, …

Jun 13, 2024
CVE-2024-37164
7.1 HIGH

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for …

Jun 13, 2024
CVE-2024-37131
7.5 HIGH

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to …

Jun 13, 2024
CVE-2024-36396
8.8 HIGH

Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

Jun 13, 2024
CVE-2024-32860
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-32859
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-32858
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-34129
7.5 HIGH

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that …

Jun 13, 2024
CVE-2024-34116
7.1 HIGH

Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in a security feature bypass. An …

Jun 13, 2024
CVE-2024-34115
7.8 HIGH

Substance3D - Stager versions 2.1.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 13, 2024
CVE-2024-34112
7.5 HIGH

ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could …

Jun 13, 2024
CVE-2024-30472
7.5 HIGH

Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this …

Jun 13, 2024
CVE-2024-20753
7.8 HIGH

Photoshop Desktop versions 24.7.3, 25.7 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Jun 13, 2024
CVE-2024-34110
7.2 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in …

Jun 13, 2024
CVE-2024-34109
7.2 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in …

Jun 13, 2024
CVE-2024-34104
8.2 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.