CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-33068
6.7 MEDIUM

Memory corruption in Audio while processing IIR config data from AFE calibration block.

Feb 6, 2024
CVE-2023-33067
6.7 MEDIUM

Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.

Feb 6, 2024
CVE-2023-33065
6.1 MEDIUM

Information disclosure in Audio while accessing AVCS services from ADSP payload.

Feb 6, 2024
CVE-2023-33064
5.5 MEDIUM

Transient DOS in Audio when invoking callback function of ASM driver.

Feb 6, 2024
CVE-2024-24808
4.7 MEDIUM

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting …

Feb 6, 2024
CVE-2024-20827
4.6 MEDIUM

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

Feb 6, 2024
CVE-2024-20826
5.5 MEDIUM

Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20825
5.5 MEDIUM

Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20824
5.5 MEDIUM

Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20823
5.5 MEDIUM

Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20822
5.5 MEDIUM

Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20820
4.4 MEDIUM

Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

Feb 6, 2024
CVE-2024-20819
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20818
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20817
6.6 MEDIUM

Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

Feb 6, 2024
CVE-2024-20814
4.0 MEDIUM

Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.

Feb 6, 2024
CVE-2024-20811
5.1 MEDIUM

Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.

Feb 6, 2024
CVE-2023-47022
6.5 MEDIUM

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to …

Feb 6, 2024
CVE-2024-24595
6.0 MEDIUM

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

Feb 5, 2024
CVE-2024-1210
5.3 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it …

Feb 5, 2024
CVE-2024-1209
5.3 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due …

Feb 5, 2024
CVE-2024-1208
5.3 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it …

Feb 5, 2024
CVE-2024-1177
5.3 MEDIUM

The WP Club Manager – WordPress Sports Club Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 5, 2024
CVE-2024-1121
5.3 MEDIUM

The Advanced Forms for ACF plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_json_file() function …

Feb 5, 2024
CVE-2024-1092
4.3 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification …

Feb 5, 2024
CVE-2024-1046
6.4 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site …

Feb 5, 2024
CVE-2024-0969
5.3 MEDIUM

The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes …

Feb 5, 2024
CVE-2024-0961
6.4 MEDIUM

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 …

Feb 5, 2024
CVE-2024-0954
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing …

Feb 5, 2024
CVE-2024-0859
4.3 MEDIUM

The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34. This is due to missing …

Feb 5, 2024
CVE-2024-0835
4.3 MEDIUM

The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the dismissed_handler function in …

Feb 5, 2024
CVE-2024-0834
6.4 MEDIUM

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 …

Feb 5, 2024
CVE-2024-0823
5.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up …

Feb 5, 2024
CVE-2024-0797
4.3 MEDIUM

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a …

Feb 5, 2024
CVE-2024-0796
4.3 MEDIUM

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Feb 5, 2024
CVE-2024-0791
4.3 MEDIUM

The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to …

Feb 5, 2024
CVE-2024-0790
5.4 MEDIUM

The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Feb 5, 2024
CVE-2024-0701
5.3 MEDIUM

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use …

Feb 5, 2024
CVE-2024-0699
6.6 MEDIUM

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Feb 5, 2024
CVE-2024-0691
5.5 MEDIUM

The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to …

Feb 5, 2024
CVE-2024-0678
6.5 MEDIUM

The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'available-days-tf' parameter in all versions up to, …

Feb 5, 2024
CVE-2024-0668
6.6 MEDIUM

The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted …

Feb 5, 2024
CVE-2024-0660
6.1 MEDIUM

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

Feb 5, 2024
CVE-2024-0659
5.5 MEDIUM

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 5, 2024
CVE-2024-0630
4.4 MEDIUM

The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, …

Feb 5, 2024
CVE-2024-0612
4.4 MEDIUM

The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in …

Feb 5, 2024
CVE-2024-0597
4.4 MEDIUM

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including …

Feb 5, 2024
CVE-2024-0586
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 5, 2024
CVE-2024-0585
5.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 5, 2024
CVE-2024-0509
6.1 MEDIUM

The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.