CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52357
7.5 HIGH

Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52097
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2022-41738
7.5 HIGH

IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: …

Feb 17, 2024
CVE-2022-41737
7.1 HIGH

IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. …

Feb 17, 2024
CVE-2024-25468
7.5 HIGH

An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.

Feb 17, 2024
CVE-2024-25298
7.2 HIGH

An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

Feb 17, 2024
CVE-2024-22727
8.3 HIGH

Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability via Ethernet LAN or USB.

Feb 17, 2024
CVE-2023-31728
7.0 HIGH

Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even …

Feb 17, 2024
CVE-2024-20956
7.3 HIGH

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). Supported versions that are affected are Prior to …

Feb 17, 2024
CVE-2024-20953
8.8 HIGH KEV

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows …

Feb 17, 2024
CVE-2024-20931
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20927
8.6 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20917
7.5 HIGH

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Log Management). The supported version that is affected is 13.5.0.0. Difficult …

Feb 17, 2024
CVE-2024-20909
7.5 HIGH

Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows unauthenticated attacker with network …

Feb 17, 2024
CVE-2024-25628
7.6 HIGH

Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being …

Feb 16, 2024
CVE-2024-0023
7.8 HIGH

In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Feb 16, 2024
CVE-2024-0021
7.8 HIGH

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic …

Feb 16, 2024
CVE-2024-0018
7.8 HIGH

In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Feb 16, 2024
CVE-2024-0015
7.8 HIGH

In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent redirection. This could lead to local escalation of …

Feb 16, 2024
CVE-2023-21165
7.8 HIGH

In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege …

Feb 16, 2024
CVE-2024-21775
8.3 HIGH

Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

Feb 16, 2024
CVE-2024-22426
7.2 HIGH

Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute …

Feb 16, 2024
CVE-2024-25466
7.8 HIGH

Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted …

Feb 16, 2024
CVE-2023-51931
7.5 HIGH

An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.

Feb 16, 2024
CVE-2023-6451
8.6 HIGH

Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.

Feb 16, 2024
CVE-2024-25415
7.2 HIGH

A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into …

Feb 16, 2024
CVE-2024-25413
7.2 HIGH

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via …

Feb 16, 2024
CVE-2024-0041
7.0 HIGH

In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of …

Feb 16, 2024
CVE-2024-0040
7.5 HIGH

In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure …

Feb 16, 2024
CVE-2024-0038
7.8 HIGH

In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of …

Feb 16, 2024
CVE-2024-0036
7.8 HIGH

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in …

Feb 16, 2024
CVE-2024-0035
7.8 HIGH

In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead …

Feb 16, 2024
CVE-2024-0034
7.8 HIGH

In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of …

Feb 16, 2024
CVE-2024-0033
7.8 HIGH

In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege …

Feb 16, 2024
CVE-2024-0029
7.8 HIGH

In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the …

Feb 16, 2024
CVE-2024-0014
7.8 HIGH

In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local …

Feb 16, 2024
CVE-2023-40115
7.8 HIGH

In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with …

Feb 15, 2024
CVE-2023-40114
7.8 HIGH

In multiple functions of MtpFfsHandle.cpp , there is a possible out of bounds write due to a use after free. This could lead to local …

Feb 15, 2024
CVE-2023-40111
7.8 HIGH

In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could …

Feb 15, 2024
CVE-2023-40110
7.8 HIGH

In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation …

Feb 15, 2024
CVE-2023-40109
7.8 HIGH

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege …

Feb 15, 2024
CVE-2023-40107
7.8 HIGH

In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no …

Feb 15, 2024
CVE-2023-40106
7.8 HIGH

In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local …

Feb 15, 2024
CVE-2023-40104
7.5 HIGH

In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with …

Feb 15, 2024
CVE-2023-40100
7.8 HIGH

In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with …

Feb 15, 2024
CVE-2024-25123
7.3 HIGH

MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable …

Feb 15, 2024
CVE-2024-23478
8.0 HIGH

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Feb 15, 2024
CVE-2024-23477
7.9 HIGH

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an …

Feb 15, 2024
CVE-2024-0622
8.8 HIGH

Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation.

Feb 15, 2024
CVE-2023-6123
7.5 HIGH

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

Feb 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.