CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20833
4.1 MEDIUM

Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory …

Mar 5, 2024
CVE-2024-20841
5.1 MEDIUM

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

Mar 5, 2024
CVE-2024-20840
5.7 MEDIUM

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using …

Mar 5, 2024
CVE-2024-20839
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to …

Mar 5, 2024
CVE-2024-20838
6.8 MEDIUM

Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20837
5.3 MEDIUM

Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own …

Mar 5, 2024
CVE-2024-20835
4.0 MEDIUM

Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.

Mar 5, 2024
CVE-2024-20832
6.4 MEDIUM

Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20831
6.4 MEDIUM

Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Mar 5, 2024
CVE-2024-20830
5.3 MEDIUM

Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

Mar 5, 2024
CVE-2024-20829
5.4 MEDIUM

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

Mar 5, 2024
CVE-2023-52432
5.9 MEDIUM

Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.

Mar 5, 2024
CVE-2024-22383
6.2 MEDIUM

Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under …

Mar 5, 2024
CVE-2024-21838
6.8 MEDIUM

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection …

Mar 5, 2024
CVE-2024-1782
6.1 MEDIUM

The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' parameter in all versions up to, and including, 1.0 …

Mar 5, 2024
CVE-2024-1769
5.3 MEDIUM

The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description data. …

Mar 5, 2024
CVE-2024-1478
5.3 MEDIUM

The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This …

Mar 5, 2024
CVE-2024-1381
6.5 MEDIUM

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, …

Mar 5, 2024
CVE-2024-1285
6.5 MEDIUM

The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Mar 5, 2024
CVE-2024-1178
5.3 MEDIUM

The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 5, 2024
CVE-2024-1095
5.3 MEDIUM

The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Mar 5, 2024
CVE-2024-1093
5.3 MEDIUM

The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic() function hooked …

Mar 5, 2024
CVE-2024-1088
5.3 MEDIUM

The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the …

Mar 5, 2024
CVE-2024-0698
6.4 MEDIUM

The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due …

Mar 5, 2024
CVE-2023-49969
4.3 MEDIUM

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

Mar 5, 2024
CVE-2023-41829
5.0 MEDIUM

An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

Mar 4, 2024
CVE-2023-41827
5.1 MEDIUM

An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on …

Mar 4, 2024
CVE-2024-2168
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 4, 2024
CVE-2024-1319
4.3 MEDIUM

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any …

Mar 4, 2024
CVE-2024-1316
6.5 MEDIUM

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor …

Mar 4, 2024
CVE-2021-47108
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check …

Mar 4, 2024
CVE-2021-47105
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: xsk: return xsk buffers back to pool when cleaning the ring Currently we only …

Mar 4, 2024
CVE-2021-47104
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/qib: Fix memory leak in qib_user_sdma_queue_pkts() The wrong goto label was used for the error …

Mar 4, 2024
CVE-2023-38360
6.1 MEDIUM

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 4, 2024
CVE-2021-47100
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix UAF when uninstall ipmi_si and ipmi_msghandler module Hi, When testing install and uninstall …

Mar 4, 2024
CVE-2021-47099
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: veth: ensure skb entering GRO are not cloned. After commit d3256efd8e8b ("veth: allow enabling NAPI …

Mar 4, 2024
CVE-2021-47096
4.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space …

Mar 4, 2024
CVE-2021-47095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi: ssif: initialize ssif_info->client early During probe ssif_info->client is dereferenced in error path. However, it …

Mar 4, 2024
CVE-2021-47093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel_pmc_core: fix memleak on registration failure In case device registration fails during module initialisation, …

Mar 4, 2024
CVE-2021-47092
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Always clear vmx->fail on emulation_required Revert a relatively recent change that set vmx->fail …

Mar 4, 2024
CVE-2021-47091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix locking in ieee80211_start_ap error path We need to hold the local->mtx to release …

Mar 4, 2024
CVE-2021-47090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() Hulk Robot reported a panic in put_page_testzero() when testing …

Mar 4, 2024
CVE-2021-47086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phonet/pep: refuse to enable an unbound pipe This ioctl() implicitly assumed that the socket was …

Mar 4, 2024
CVE-2023-5451
6.1 MEDIUM

Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of …

Mar 4, 2024
CVE-2023-38362
5.3 MEDIUM

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.

Mar 4, 2024
CVE-2022-43890
5.3 MEDIUM

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. …

Mar 4, 2024
CVE-2024-27680
6.1 MEDIUM

Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."

Mar 4, 2024
CVE-2024-27668
6.1 MEDIUM

Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'

Mar 4, 2024
CVE-2024-27684
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML …

Mar 4, 2024
CVE-2023-33090
5.5 MEDIUM

Transient DOS while processing channel information for speaker protection v2 module in ADSP.

Mar 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.