CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42236
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy() Userspace provided string 's' could trivially have …

Aug 7, 2024
CVE-2024-42235
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add NULL pointer check to crst_table_free() base_crst_free() crst_table_free() used to work with NULL pointers …

Aug 7, 2024
CVE-2024-42234
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: fix crashes from deferred split racing folio migration Even on 6.10-rc6, I've been seeing …

Aug 7, 2024
CVE-2024-42232
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: libceph: fix race between delayed_work() and ceph_monc_stop() The way the delayed work is handled in …

Aug 7, 2024
CVE-2024-41432
5.3 MEDIUM

An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any …

Aug 7, 2024
CVE-2024-41252
6.5 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view …

Aug 7, 2024
CVE-2024-41251
6.5 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view …

Aug 7, 2024
CVE-2024-41249
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.

Aug 7, 2024
CVE-2024-41248
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add …

Aug 7, 2024
CVE-2024-41247
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add …

Aug 7, 2024
CVE-2024-41246
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.

Aug 7, 2024
CVE-2024-7580
6.3 MEDIUM

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 7, 2024
CVE-2024-7579
6.3 MEDIUM

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen …

Aug 7, 2024
CVE-2024-43045
6.3 MEDIUM

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access …

Aug 7, 2024
CVE-2024-7355
4.9 MEDIUM

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, …

Aug 7, 2024
CVE-2024-7353
5.4 MEDIUM

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, …

Aug 7, 2024
CVE-2024-7267
6.5 MEDIUM

Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP …

Aug 7, 2024
CVE-2024-7266
4.3 MEDIUM

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the …

Aug 7, 2024
CVE-2024-42222
4.3 MEDIUM

In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. …

Aug 7, 2024
CVE-2024-6494
6.1 MEDIUM

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site …

Aug 7, 2024
CVE-2024-3973
4.8 MEDIUM

The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Aug 7, 2024
CVE-2024-37403
5.5 MEDIUM

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path …

Aug 7, 2024
CVE-2024-34788
6.5 MEDIUM

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

Aug 7, 2024
CVE-2024-34636
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34635
4.0 MEDIUM

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34634
4.0 MEDIUM

Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34633
4.0 MEDIUM

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34632
4.0 MEDIUM

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34631
5.5 MEDIUM

Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34630
5.5 MEDIUM

Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34629
5.5 MEDIUM

Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34628
5.5 MEDIUM

Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34627
5.5 MEDIUM

Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34626
5.5 MEDIUM

Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34625
5.5 MEDIUM

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34624
5.5 MEDIUM

Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34621
5.5 MEDIUM

Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34618
4.0 MEDIUM

Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

Aug 7, 2024
CVE-2024-34617
4.0 MEDIUM

Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

Aug 7, 2024
CVE-2024-34616
5.1 MEDIUM

Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

Aug 7, 2024
CVE-2024-34615
5.1 MEDIUM

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

Aug 7, 2024
CVE-2024-34613
4.0 MEDIUM

Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Aug 7, 2024
CVE-2024-34611
5.1 MEDIUM

Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34610
5.1 MEDIUM

Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

Aug 7, 2024
CVE-2024-34609
6.2 MEDIUM

Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34608
6.2 MEDIUM

Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34607
6.2 MEDIUM

Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34606
6.2 MEDIUM

Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34605
6.2 MEDIUM

Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34604
6.2 MEDIUM

Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.