CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9147
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects …

Nov 4, 2024
CVE-2024-51561
7.5 HIGH

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability …

Nov 4, 2024
CVE-2024-51560
4.3 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51559
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by …

Nov 4, 2024
CVE-2024-51558
9.8 CRITICAL

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could …

Nov 4, 2024
CVE-2024-51557
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51556
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-36485
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

Nov 4, 2024
CVE-2024-10523
4.6 MEDIUM

This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical …

Nov 4, 2024
CVE-2024-10035
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used …

Nov 4, 2024
CVE-2024-51661
9.1 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue …

Nov 4, 2024
CVE-2024-48878
8.3 HIGH

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Nov 4, 2024
CVE-2024-10389
7.5 HIGH

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction …

Nov 4, 2024
CVE-2024-38424
7.8 HIGH

Memory corruption during GNSS HAL process initialization.

Nov 4, 2024
CVE-2024-38423
7.8 HIGH

Memory corruption while processing GPU page table switch.

Nov 4, 2024
CVE-2024-38422
7.8 HIGH

Memory corruption while processing voice packet with arbitrary data received from ADSP.

Nov 4, 2024
CVE-2024-38421
7.8 HIGH

Memory corruption while processing GPU commands.

Nov 4, 2024
CVE-2024-38419
7.8 HIGH

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Nov 4, 2024
CVE-2024-38415
7.8 HIGH

Memory corruption while handling session errors from firmware.

Nov 4, 2024
CVE-2024-38410
7.8 HIGH

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Nov 4, 2024
CVE-2024-38409
7.8 HIGH

Memory corruption while station LL statistic handling.

Nov 4, 2024
CVE-2024-38408
8.2 HIGH

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Nov 4, 2024
CVE-2024-38407
7.8 HIGH

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38406
7.8 HIGH

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38405
7.5 HIGH

Transient DOS while processing the CU information from RNR IE.

Nov 4, 2024
CVE-2024-38403
7.5 HIGH

Transient DOS while parsing BTM ML IE when per STA profile is not included.

Nov 4, 2024
CVE-2024-33068
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Nov 4, 2024
CVE-2024-33033
6.7 MEDIUM

Memory corruption while processing IOCTL calls to unmap the buffers.

Nov 4, 2024
CVE-2024-33032
6.7 MEDIUM

Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

Nov 4, 2024
CVE-2024-33031
6.7 MEDIUM

Memory corruption while processing the update SIM PB records request.

Nov 4, 2024
CVE-2024-33030
6.7 MEDIUM

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

Nov 4, 2024
CVE-2024-33029
6.7 MEDIUM

Memory corruption while handling the PDR in driver for getting the remote heap maps.

Nov 4, 2024
CVE-2024-23590
9.1 CRITICAL

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, …

Nov 4, 2024
CVE-2024-23386
6.7 MEDIUM

memory corruption when WiFi display APIs are invoked with large random inputs.

Nov 4, 2024
CVE-2024-23385
7.5 HIGH

Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

Nov 4, 2024
CVE-2024-23377
6.7 MEDIUM

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already …

Nov 4, 2024
CVE-2024-48342

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Nov 4, 2024
CVE-2024-10761
4.3 MEDIUM

A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} …

Nov 4, 2024
CVE-2024-10760
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. …

Nov 4, 2024
CVE-2024-10759
6.3 MEDIUM

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The …

Nov 4, 2024
CVE-2024-10758
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-10757
3.5 LOW

A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Shopping Portal 2.0. Affected by this issue is some unknown functionality of …

Nov 4, 2024
CVE-2024-10756
3.5 LOW

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. …

Nov 4, 2024
CVE-2024-10755
3.5 LOW

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation …

Nov 4, 2024
CVE-2024-10754
3.5 LOW

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 4, 2024
CVE-2024-20124
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20123
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20122
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20121
6.7 MEDIUM

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20120
6.7 MEDIUM

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.