CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22009
7.1 HIGH

In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-22008
7.8 HIGH

In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-22005
8.4 HIGH

there is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. …

Mar 11, 2024
CVE-2024-26620
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter …

Mar 11, 2024
CVE-2024-26619
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix module loading free order Reverse order of kfree calls to resolve use-after-free error.

Mar 11, 2024
CVE-2024-26617
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: move mmu notification mechanism inside mm lock Move mmu notification mechanism inside mm lock …

Mar 11, 2024
CVE-2024-26616
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: scrub: avoid use-after-free when chunk length is not 64K aligned [BUG] There is a …

Mar 11, 2024
CVE-2024-26610
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means …

Mar 11, 2024
CVE-2024-26608
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix global oob in ksmbd_nl_policy Similar to a reported issue (check the commit b33fb5b801c6 …

Mar 11, 2024
CVE-2024-1068
7.2 HIGH

The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a …

Mar 11, 2024
CVE-2023-52495
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink_altmode: fix port sanity check The PMIC GLINK altmode driver currently supports at …

Mar 11, 2024
CVE-2023-52494
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Add alignment check for event ring read pointer Though we do check …

Mar 11, 2024
CVE-2023-52491
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run In …

Mar 11, 2024
CVE-2024-23717
8.8 HIGH

In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation …

Mar 11, 2024
CVE-2024-1696
7.8 HIGH

In Santesoft Sante FFT Imaging versions 1.4.1 and prior once a user opens a malicious DCM file on affected FFT Imaging installations, a local attacker …

Mar 11, 2024
CVE-2024-0051
7.8 HIGH

In onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-0050
7.8 HIGH

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could lead to a local non-security …

Mar 11, 2024
CVE-2024-0049
7.8 HIGH

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege …

Mar 11, 2024
CVE-2024-0048
7.8 HIGH

In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to …

Mar 11, 2024
CVE-2024-0046
7.8 HIGH

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation …

Mar 11, 2024
CVE-2024-23612
7.8 HIGH

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially …

Mar 11, 2024
CVE-2024-23611
7.8 HIGH

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Mar 11, 2024
CVE-2024-23610
7.8 HIGH

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Mar 11, 2024
CVE-2024-23609
7.8 HIGH

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially …

Mar 11, 2024
CVE-2024-23608
7.8 HIGH

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Mar 11, 2024
CVE-2024-0670
8.8 HIGH

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Mar 11, 2024
CVE-2024-28816
7.1 HIGH

Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.

Mar 11, 2024
CVE-2024-2353
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of …

Mar 10, 2024
CVE-2024-28757
7.5 HIGH

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Mar 10, 2024
CVE-2024-25501
8.8 HIGH

An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.

Mar 9, 2024
CVE-2024-25951
8.0 HIGH

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

Mar 9, 2024
CVE-2023-46426
8.8 HIGH

Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component …

Mar 9, 2024
CVE-2023-50015
8.8 HIGH

An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity …

Mar 9, 2024
CVE-2023-49341
7.5 HIGH

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm …

Mar 9, 2024
CVE-2024-28184
7.4 HIGH

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a …

Mar 9, 2024
CVE-2024-28754
7.5 HIGH

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.

Mar 9, 2024
CVE-2024-2339
8.0 HIGH

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function …

Mar 8, 2024
CVE-2024-2338
8.0 HIGH

PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. …

Mar 8, 2024
CVE-2024-27613
7.3 HIGH

Numbas editor before 7.3 mishandles reading of themes and extensions.

Mar 8, 2024
CVE-2024-2282
7.3 HIGH

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of …

Mar 8, 2024
CVE-2024-26313
7.3 HIGH

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this …

Mar 8, 2024
CVE-2024-23294
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.

Mar 8, 2024
CVE-2024-23288
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS …

Mar 8, 2024
CVE-2024-23286
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, …

Mar 8, 2024
CVE-2024-23278
8.6 HIGH

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, …

Mar 8, 2024
CVE-2024-23276
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may …

Mar 8, 2024
CVE-2024-23274
7.8 HIGH

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app …

Mar 8, 2024
CVE-2024-23270
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS …

Mar 8, 2024
CVE-2024-23268
7.8 HIGH

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app …

Mar 8, 2024
CVE-2024-23265
7.8 HIGH

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.