CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-34954
7.8 HIGH

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34953
7.8 HIGH

Foxit PDF Reader Annotation Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

May 7, 2024
CVE-2021-34952
7.8 HIGH

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34950
7.8 HIGH

Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34948
7.8 HIGH

Foxit PDF Reader Square Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34947
8.8 HIGH

NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. …

May 7, 2024
CVE-2024-4030
7.1 HIGH

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, …

May 7, 2024
CVE-2024-34346
8.4 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged …

May 7, 2024
CVE-2024-27273
8.1 HIGH

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with …

May 7, 2024
CVE-2024-23713
7.8 HIGH

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of …

May 7, 2024
CVE-2024-23710
7.8 HIGH

In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. …

May 7, 2024
CVE-2024-23708
7.8 HIGH

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could …

May 7, 2024
CVE-2024-23707
7.8 HIGH

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional …

May 7, 2024
CVE-2024-23706
7.8 HIGH

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of …

May 7, 2024
CVE-2024-23705
7.8 HIGH

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation …

May 7, 2024
CVE-2024-23704
7.8 HIGH

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local …

May 7, 2024
CVE-2024-0043
7.8 HIGH

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the …

May 7, 2024
CVE-2024-0042
7.8 HIGH

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass …

May 7, 2024
CVE-2024-0025
7.8 HIGH

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with …

May 7, 2024
CVE-2024-0024
7.8 HIGH

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to …

May 7, 2024
CVE-2024-34315
7.5 HIGH

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers …

May 7, 2024
CVE-2024-25513
7.8 HIGH

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.

May 7, 2024
CVE-2024-25512
8.1 HIGH

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.aspx.

May 7, 2024
CVE-2024-33149
8.1 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.

May 7, 2024
CVE-2024-33148
7.3 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

May 7, 2024
CVE-2024-33147
8.8 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.

May 7, 2024
CVE-2024-29207
7.5 HIGH

An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Products: UniFi Connect …

May 7, 2024
CVE-2024-29150
8.8 HIGH

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is …

May 7, 2024
CVE-2024-29149
7.4 HIGH

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker …

May 7, 2024
CVE-2024-33144
8.8 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.

May 7, 2024
CVE-2024-33139
7.5 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

May 7, 2024
CVE-2024-34523
7.5 HIGH

AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through …

May 7, 2024
CVE-2024-34342
7.1 HIGH

react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which …

May 7, 2024
CVE-2024-34084
7.5 HIGH

Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and …

May 7, 2024
CVE-2024-32663
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 …

May 7, 2024
CVE-2024-32371
7.5 HIGH

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing …

May 7, 2024
CVE-2024-33782
7.5 HIGH

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33781
7.5 HIGH

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-31456
7.7 HIGH

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. …

May 7, 2024
CVE-2024-29889
7.1 HIGH

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved …

May 7, 2024
CVE-2024-4600
7.1 HIGH

Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users into performing critical actions, such …

May 7, 2024
CVE-2024-4538
7.5 HIGH

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket by creating a …

May 7, 2024
CVE-2024-4537
7.5 HIGH

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to …

May 7, 2024
CVE-2024-4599
7.5 HIGH

Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a …

May 7, 2024
CVE-2024-4582
7.3 HIGH

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP …

May 7, 2024
CVE-2024-22472
8.1 HIGH

A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all …

May 7, 2024
CVE-2024-29941
8.0 HIGH

Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and …

May 6, 2024
CVE-2024-30973
8.8 HIGH

An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST …

May 6, 2024
CVE-2024-34534
7.3 HIGH

A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the …

May 6, 2024
CVE-2024-34533
7.3 HIGH

A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker …

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.