CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8413
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit …

Sep 4, 2024
CVE-2024-7870
6.5 MEDIUM

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all …

Sep 4, 2024
CVE-2024-8318
6.4 MEDIUM

The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 …

Sep 4, 2024
CVE-2024-8123
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Sep 4, 2024
CVE-2024-8121
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check …

Sep 4, 2024
CVE-2024-8119
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up …

Sep 4, 2024
CVE-2024-8117
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up …

Sep 4, 2024
CVE-2024-8106
6.5 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 …

Sep 4, 2024
CVE-2024-8325
6.4 MEDIUM

The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding …

Sep 4, 2024
CVE-2024-7786
5.3 MEDIUM

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Sep 4, 2024
CVE-2024-6889
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6888
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6722
4.8 MEDIUM

The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow …

Sep 4, 2024
CVE-2024-6020
6.1 MEDIUM

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, …

Sep 4, 2024
CVE-2024-34661
4.3 MEDIUM

Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering …

Sep 4, 2024
CVE-2024-34658
4.0 MEDIUM

Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

Sep 4, 2024
CVE-2024-34655
6.2 MEDIUM

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

Sep 4, 2024
CVE-2024-34654
6.2 MEDIUM

Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

Sep 4, 2024
CVE-2024-34653
4.6 MEDIUM

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

Sep 4, 2024
CVE-2024-34652
4.0 MEDIUM

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

Sep 4, 2024
CVE-2024-34651
6.2 MEDIUM

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

Sep 4, 2024
CVE-2024-34650
4.0 MEDIUM

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

Sep 4, 2024
CVE-2024-34648
5.1 MEDIUM

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

Sep 4, 2024
CVE-2024-34647
4.0 MEDIUM

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper …

Sep 4, 2024
CVE-2024-34646
6.6 MEDIUM

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

Sep 4, 2024
CVE-2024-34645
6.1 MEDIUM

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

Sep 4, 2024
CVE-2024-34644
4.4 MEDIUM

Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is …

Sep 4, 2024
CVE-2024-34643
4.4 MEDIUM

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction …

Sep 4, 2024
CVE-2024-34642
4.6 MEDIUM

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

Sep 4, 2024
CVE-2024-34641
5.1 MEDIUM

Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

Sep 4, 2024
CVE-2024-34639
4.6 MEDIUM

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

Sep 4, 2024
CVE-2024-34638
6.7 MEDIUM

Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

Sep 4, 2024
CVE-2024-34637
6.2 MEDIUM

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 …

Sep 4, 2024
CVE-2024-8298
6.2 MEDIUM

Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45449
5.1 MEDIUM

Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45448
4.1 MEDIUM

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45447
4.4 MEDIUM

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45446
5.5 MEDIUM

Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45445
4.0 MEDIUM

Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45444
5.5 MEDIUM

Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45443
6.1 MEDIUM

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Sep 4, 2024
CVE-2024-45450
4.0 MEDIUM

Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45442
5.1 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45441
6.2 MEDIUM

Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-42039
4.3 MEDIUM

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-41927
4.6 MEDIUM

Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials …

Sep 4, 2024
CVE-2024-45619
4.3 MEDIUM

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-8399
4.7 MEDIUM

Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.

Sep 3, 2024
CVE-2024-4629
6.5 MEDIUM

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple …

Sep 3, 2024
CVE-2024-45678
4.2 MEDIUM

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires …

Sep 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.