CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45195
7.5 HIGH KEV

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes …

Sep 4, 2024
CVE-2024-8318
6.4 MEDIUM

The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 …

Sep 4, 2024
CVE-2024-8123
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Sep 4, 2024
CVE-2024-8121
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check …

Sep 4, 2024
CVE-2024-8119
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up …

Sep 4, 2024
CVE-2024-8117
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up …

Sep 4, 2024
CVE-2024-8106
6.5 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 …

Sep 4, 2024
CVE-2024-8104
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via …

Sep 4, 2024
CVE-2024-8102
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 4, 2024
CVE-2024-8325
6.4 MEDIUM

The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding …

Sep 4, 2024
CVE-2024-7786
5.3 MEDIUM

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Sep 4, 2024
CVE-2024-6926
9.8 CRITICAL

The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Sep 4, 2024
CVE-2024-6889
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6888
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6722
4.8 MEDIUM

The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow …

Sep 4, 2024
CVE-2024-6020
6.1 MEDIUM

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, …

Sep 4, 2024
CVE-2024-34661
4.3 MEDIUM

Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering …

Sep 4, 2024
CVE-2024-34660
7.3 HIGH

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34659
7.5 HIGH

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

Sep 4, 2024
CVE-2024-34658
4.0 MEDIUM

Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

Sep 4, 2024
CVE-2024-34657
8.6 HIGH

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34656
7.3 HIGH

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34655
6.2 MEDIUM

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

Sep 4, 2024
CVE-2024-34654
6.2 MEDIUM

Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

Sep 4, 2024
CVE-2024-34653
4.6 MEDIUM

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

Sep 4, 2024
CVE-2024-34652
4.0 MEDIUM

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

Sep 4, 2024
CVE-2024-34651
6.2 MEDIUM

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

Sep 4, 2024
CVE-2024-34650
4.0 MEDIUM

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

Sep 4, 2024
CVE-2024-34649
2.4 LOW

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

Sep 4, 2024
CVE-2024-34648
5.1 MEDIUM

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

Sep 4, 2024
CVE-2024-34647
4.0 MEDIUM

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper …

Sep 4, 2024
CVE-2024-34646
6.6 MEDIUM

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

Sep 4, 2024
CVE-2024-34645
6.1 MEDIUM

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

Sep 4, 2024
CVE-2024-34644
4.4 MEDIUM

Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is …

Sep 4, 2024
CVE-2024-34643
4.4 MEDIUM

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction …

Sep 4, 2024
CVE-2024-34642
4.6 MEDIUM

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

Sep 4, 2024
CVE-2024-34641
5.1 MEDIUM

Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

Sep 4, 2024
CVE-2024-34640
3.3 LOW

Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

Sep 4, 2024
CVE-2024-34639
4.6 MEDIUM

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

Sep 4, 2024
CVE-2024-34638
6.7 MEDIUM

Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

Sep 4, 2024
CVE-2024-34637
6.2 MEDIUM

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 …

Sep 4, 2024
CVE-2024-8298
6.2 MEDIUM

Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-7950
9.8 CRITICAL

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary …

Sep 4, 2024
CVE-2024-45449
5.1 MEDIUM

Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45448
4.1 MEDIUM

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45447
4.4 MEDIUM

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45446
5.5 MEDIUM

Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45445
4.0 MEDIUM

Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45444
5.5 MEDIUM

Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45443
6.1 MEDIUM

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.