CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33113
5.3 MEDIUM

D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

May 6, 2024
CVE-2024-33111
5.4 MEDIUM

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

May 6, 2024
CVE-2023-43530
5.9 MEDIUM

Memory corruption in HLOS while checking for the storage type.

May 6, 2024
CVE-2023-43528
6.1 MEDIUM

Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

May 6, 2024
CVE-2023-43527
6.8 MEDIUM

Information disclosure while parsing dts header atom in Video.

May 6, 2024
CVE-2023-43526
6.7 MEDIUM

Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

May 6, 2024
CVE-2023-43525
6.7 MEDIUM

Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

May 6, 2024
CVE-2023-43524
6.7 MEDIUM

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

May 6, 2024
CVE-2023-43521
6.7 MEDIUM

Memory corruption when multiple listeners are being registered with the same file descriptor.

May 6, 2024
CVE-2024-33752
6.3 MEDIUM

An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit …

May 6, 2024
CVE-2024-33829
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

May 6, 2024
CVE-2023-49676
5.5 MEDIUM

An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

May 6, 2024
CVE-2023-6854
6.4 MEDIUM

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 …

May 6, 2024
CVE-2024-23193
5.3 MEDIUM

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same …

May 6, 2024
CVE-2024-23188
6.5 MEDIUM

Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is …

May 6, 2024
CVE-2024-23187
6.5 MEDIUM

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious …

May 6, 2024
CVE-2024-23186
6.5 MEDIUM

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from …

May 6, 2024
CVE-2024-3755
5.4 MEDIUM

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-3752
5.4 MEDIUM

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 6, 2024
CVE-2024-0904
5.9 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-20060
5.9 MEDIUM

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20059
6.7 MEDIUM

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20058
4.4 MEDIUM

In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

May 6, 2024
CVE-2024-20056
6.7 MEDIUM

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20021
6.7 MEDIUM

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local …

May 6, 2024
CVE-2023-32873
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

May 6, 2024
CVE-2023-32871
5.3 MEDIUM

In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional …

May 6, 2024
CVE-2024-4511
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. This affects an unknown part of the component Message …

May 6, 2024
CVE-2024-4510
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 6, 2024
CVE-2024-4509
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 6, 2024
CVE-2024-4508
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. …

May 6, 2024
CVE-2024-4507
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The …

May 6, 2024
CVE-2024-34529
4.8 MEDIUM

Nebari through 2024.4.1 prints the temporary Keycloak root password.

May 6, 2024
CVE-2024-34525
5.3 MEDIUM

FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.

May 6, 2024
CVE-2024-4506
4.7 MEDIUM

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The …

May 5, 2024
CVE-2024-4505
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The …

May 5, 2024
CVE-2024-4504
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of …

May 5, 2024
CVE-2024-4503
4.7 MEDIUM

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. …

May 5, 2024
CVE-2024-4502
4.7 MEDIUM

A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation …

May 5, 2024
CVE-2024-34519
6.8 MEDIUM

Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an …

May 5, 2024
CVE-2024-4501
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file …

May 5, 2024
CVE-2024-34509
5.3 MEDIUM

dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

May 5, 2024
CVE-2024-34508
4.3 MEDIUM

dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

May 5, 2024
CVE-2024-34500
6.1 MEDIUM

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface …

May 5, 2024
CVE-2024-4500
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Employee/edit-photo.php. …

May 5, 2024
CVE-2024-34490
5.1 MEDIUM

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local …

May 5, 2024
CVE-2024-34484
5.3 MEDIUM

OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.

May 5, 2024
CVE-2024-34476
5.3 MEDIUM

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for …

May 5, 2024
CVE-2024-34473
5.3 MEDIUM

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt …

May 4, 2024
CVE-2024-34468
6.1 MEDIUM

Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

May 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.