CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0022
5.5 MEDIUM

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local …

May 7, 2024
CVE-2023-40694
6.2 MEDIUM

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force …

May 7, 2024
CVE-2024-4559
6.5 MEDIUM

Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 7, 2024
CVE-2024-34314
4.9 MEDIUM

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers …

May 7, 2024
CVE-2024-34517
6.5 MEDIUM

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

May 7, 2024
CVE-2024-34397
5.2 MEDIUM

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted …

May 7, 2024
CVE-2023-42757
4.2 MEDIUM

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new …

May 7, 2024
CVE-2024-33860
6.5 MEDIUM

An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System …

May 7, 2024
CVE-2024-33859
6.1 MEDIUM

An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.

May 7, 2024
CVE-2024-33161
5.3 MEDIUM

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.

May 7, 2024
CVE-2024-29209
6.0 MEDIUM

A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely …

May 7, 2024
CVE-2024-27982
6.5 MEDIUM

The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP …

May 7, 2024
CVE-2024-34341
5.4 MEDIUM

Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from …

May 7, 2024
CVE-2024-33858
5.3 MEDIUM

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be …

May 7, 2024
CVE-2024-33856
5.3 MEDIUM

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot …

May 7, 2024
CVE-2024-33748
4.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.

May 7, 2024
CVE-2024-4595
6.3 MEDIUM

A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file …

May 7, 2024
CVE-2024-4594
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/sys_safe.php. The manipulation leads to …

May 7, 2024
CVE-2024-33122
6.3 MEDIUM

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.

May 7, 2024
CVE-2024-32867
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of …

May 7, 2024
CVE-2024-32664
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets …

May 7, 2024
CVE-2024-32369
4.3 MEDIUM

SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the …

May 7, 2024
CVE-2024-4593
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation …

May 7, 2024
CVE-2024-4592
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request …

May 7, 2024
CVE-2024-4591
4.3 MEDIUM

A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site …

May 7, 2024
CVE-2024-4590
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. …

May 7, 2024
CVE-2024-33783
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33780
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-28148
4.3 MEDIUM

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects …

May 7, 2024
CVE-2024-4589
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. …

May 7, 2024
CVE-2024-4588
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads …

May 7, 2024
CVE-2024-4587
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7 and classified as problematic. This issue affects some unknown processing of the file /src/dede/tpl.php. The manipulation leads to …

May 7, 2024
CVE-2024-4586
4.3 MEDIUM

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/shops_delivery.php. The manipulation leads to …

May 7, 2024
CVE-2024-4536
6.8 MEDIUM

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from …

May 7, 2024
CVE-2023-7240
5.8 MEDIUM

An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open …

May 7, 2024
CVE-2023-31234
6.3 MEDIUM

Missing Authorization vulnerability in Tilda Publishing.This issue affects Tilda Publishing: from n/a through 0.3.23.

May 7, 2024
CVE-2024-4601
6.7 MEDIUM

An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perform a brute force attack …

May 7, 2024
CVE-2024-4585
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to …

May 7, 2024
CVE-2024-4584
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Faraday GM8181 and GM828x up to 20240429. Affected by this issue is some unknown …

May 7, 2024
CVE-2024-4583
5.3 MEDIUM

A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the …

May 7, 2024
CVE-2023-6810
4.3 MEDIUM

The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function …

May 7, 2024
CVE-2024-3759
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

May 7, 2024
CVE-2024-3758
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

May 7, 2024
CVE-2024-27217
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

May 7, 2024
CVE-2024-23808
5.2 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL …

May 7, 2024
CVE-2024-20872
6.2 MEDIUM

Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

May 7, 2024
CVE-2024-20871
4.9 MEDIUM

Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

May 7, 2024
CVE-2024-20870
5.1 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege …

May 7, 2024
CVE-2024-20869
5.5 MEDIUM

Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.

May 7, 2024
CVE-2024-20868
4.4 MEDIUM

Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.

May 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.