CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8004
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Sep 2, 2024
CVE-2024-7939
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-7938
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Sep 2, 2024
CVE-2024-7932
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-5148
7.5 HIGH

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a …

Sep 2, 2024
CVE-2024-38858
6.1 MEDIUM

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Sep 2, 2024
CVE-2024-38402
7.8 HIGH

Memory corruption while processing IOCTL call for getting group info.

Sep 2, 2024
CVE-2024-38401
7.8 HIGH

Memory corruption while processing concurrent IOCTL calls.

Sep 2, 2024
CVE-2024-33060
8.4 HIGH

Memory corruption when two threads try to map and unmap a single node simultaneously.

Sep 2, 2024
CVE-2024-33057
7.5 HIGH

Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.

Sep 2, 2024
CVE-2024-33054
7.8 HIGH

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

Sep 2, 2024
CVE-2024-33052
7.8 HIGH

Memory corruption when user provides data for FM HCI command control operations.

Sep 2, 2024
CVE-2024-33051
7.5 HIGH

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

Sep 2, 2024
CVE-2024-33050
7.5 HIGH

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

Sep 2, 2024
CVE-2024-33048
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

Sep 2, 2024
CVE-2024-33047
8.4 HIGH

Memory corruption when the captureRead QDCM command is invoked from user-space.

Sep 2, 2024
CVE-2024-33045
8.4 HIGH

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Sep 2, 2024
CVE-2024-33043
5.5 MEDIUM

Transient DOS while handling PS event when Program Service name length offset value is set to 255.

Sep 2, 2024
CVE-2024-33042
7.8 HIGH

Memory corruption when Alternative Frequency offset value is set to 255.

Sep 2, 2024
CVE-2024-33038
7.8 HIGH

Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

Sep 2, 2024
CVE-2024-33035
8.4 HIGH

Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

Sep 2, 2024
CVE-2024-33016
6.8 MEDIUM

memory corruption when an invalid firehose patch command is invoked.

Sep 2, 2024
CVE-2024-23365
8.4 HIGH

Memory corruption while releasing shared resources in MinkSocket listener thread.

Sep 2, 2024
CVE-2024-23364
7.5 HIGH

Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air …

Sep 2, 2024
CVE-2024-23362
7.1 HIGH

Cryptographic issue while parsing RSA keys in COBR format.

Sep 2, 2024
CVE-2024-23359
8.2 HIGH

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

Sep 2, 2024
CVE-2024-23358
7.5 HIGH

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

Sep 2, 2024
CVE-2024-7692
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Sep 2, 2024
CVE-2024-7691
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against …

Sep 2, 2024
CVE-2024-7690
4.3 MEDIUM

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 2, 2024
CVE-2024-7354
6.1 MEDIUM

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting …

Sep 2, 2024
CVE-2024-8365
6.2 MEDIUM

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token …

Sep 2, 2024
CVE-2024-7871
8.8 HIGH

SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-45528
5.4 MEDIUM

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

Sep 2, 2024
CVE-2024-45527
6.1 MEDIUM

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can …

Sep 2, 2024
CVE-2024-43776
8.8 HIGH

SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43775
8.8 HIGH

SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via …

Sep 2, 2024
CVE-2024-43774
8.8 HIGH

SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands …

Sep 2, 2024
CVE-2024-43773
9.8 CRITICAL

SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via …

Sep 2, 2024
CVE-2024-43772
9.8 CRITICAL

SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via …

Sep 2, 2024
CVE-2024-41160
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-41157
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-39816
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024
CVE-2024-39775
6.5 MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-39612
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-38386
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024
CVE-2024-38382
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Sep 2, 2024
CVE-2024-28044
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.

Sep 2, 2024
CVE-2024-20089
7.5 HIGH

In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional …

Sep 2, 2024
CVE-2024-20088
4.4 MEDIUM

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.