CVE Database

4811+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3320
3.5 LOW

A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation …

Apr 5, 2024
CVE-2024-30252
2.6 LOW

Livemarks is a browser extension that provides RSS feed bookmark folders. Versions of Livemarks prior to 3.7 are vulnerable to cross-site request forgery. A malicious …

Apr 4, 2024
CVE-2024-30266
3.3 LOW

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly …

Apr 4, 2024
CVE-2024-30260
3.9 LOW

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. …

Apr 4, 2024
CVE-2024-30261
2.6 LOW

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests …

Apr 4, 2024
CVE-2024-3270
3.8 LOW

A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to …

Apr 3, 2024
CVE-2024-3181
3.1 LOW

Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search Field. Prior to the …

Apr 3, 2024
CVE-2024-3180
3.1 LOW

Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file. Stored XSS could be …

Apr 3, 2024
CVE-2024-3179
3.1 LOW

Concrete CMS version 9 before 9.2.8 and previous versions before 8.5.16 are vulnerable to Stored XSS in the Custom Class page editing. Prior to the …

Apr 3, 2024
CVE-2024-3178
3.1 LOW

Concrete CMS versions 9 below 9.2.8 and versions below 8.5.16 are vulnerable to Cross-site Scripting (XSS) in the Advanced File Search Filter. Prior to the …

Apr 3, 2024
CVE-2024-2753
2.0 LOW

Concrete CMS version 9 before 9.2.8 and previous versions prior to 8.5.16 is vulnerable to Stored XSS on the calendar color settings screen since Information …

Apr 3, 2024
CVE-2024-30329
3.3 LOW

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User …

Apr 3, 2024
CVE-2024-27345
3.3 LOW

Kofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax …

Apr 3, 2024
CVE-2024-26764
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio If kiocb_set_cancel_fn() is called for I/O submitted …

Apr 3, 2024
CVE-2024-3248
2.9 LOW

In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.

Apr 2, 2024
CVE-2024-3247
2.9 LOW

In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.

Apr 2, 2024
CVE-2024-3202
3.7 LOW

A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component …

Apr 2, 2024
CVE-2024-30364
3.3 LOW

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

Apr 2, 2024
CVE-2024-30356
3.3 LOW

Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30350
3.3 LOW

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30347
3.3 LOW

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

Apr 2, 2024
CVE-2024-30340
3.3 LOW

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30808
2.7 LOW

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by …

Apr 2, 2024
CVE-2024-29948
3.8 LOW

There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable …

Apr 2, 2024
CVE-2024-29947
2.7 LOW

There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may …

Apr 2, 2024
CVE-2023-6950
3.0 LOW

An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious …

Apr 2, 2024
CVE-2023-6948
3.0 LOW

A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could …

Apr 2, 2024
CVE-2023-51453
3.0 LOW

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2023-51452
3.0 LOW

A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to …

Apr 2, 2024
CVE-2024-2745
3.3 LOW

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when …

Apr 2, 2024
CVE-2024-29086
3.3 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

Apr 2, 2024
CVE-2024-22180
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

Apr 2, 2024
CVE-2024-22177
3.3 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.

Apr 2, 2024
CVE-2024-21834
3.3 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

Apr 2, 2024
CVE-2024-3141
2.4 LOW

A vulnerability has been found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This vulnerability affects unknown code of the file …

Apr 1, 2024
CVE-2024-3140
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file /classes/Users.php?f=save. …

Apr 1, 2024
CVE-2024-3138
3.5 LOW

** DISPUTED ** A vulnerability was found in francoisjacquet RosarioSIS 11.5.1. It has been rated as problematic. This issue affects some unknown processing of the …

Apr 1, 2024
CVE-2024-27332
3.3 LOW

PDF-XChange Editor JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27331
3.3 LOW

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27330
3.3 LOW

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-3128
2.4 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Replify-Messenger 1.0 on Android. This issue affects some unknown …

Apr 1, 2024
CVE-2024-3125
2.4 LOW

A vulnerability classified as problematic was found in Zebra ZTC GK420d 1.0. This vulnerability affects unknown code of the file /settings of the component Alert …

Apr 1, 2024
CVE-2024-3124
2.4 LOW

A vulnerability classified as problematic has been found in fridgecow smartalarm 1.8.1 on Android. This affects an unknown part of the file androidmanifest.xml of the …

Apr 1, 2024
CVE-2022-4966
3.5 LOW

A vulnerability was found in sequentech admin-console up to 6.1.7 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Apr 1, 2024
CVE-2024-20051
2.3 LOW

In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges …

Apr 1, 2024
CVE-2024-20045
2.3 LOW

In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure …

Apr 1, 2024
CVE-2014-125110
3.5 LOW

A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback …

Apr 1, 2024
CVE-2023-50311
3.1 LOW

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker that could reveal through debugging or error messages.

Mar 31, 2024
CVE-2020-36828
3.5 LOW

A vulnerability was found in DiscuzX up to 3.4-20200818. It has been classified as problematic. Affected is the function show_next_step of the file upload/install/include/install_function.php. The …

Mar 31, 2024
CVE-2017-20191
3.5 LOW

A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js …

Mar 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.