CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33019
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping action frame.

Aug 5, 2024
CVE-2024-33018
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.

Aug 5, 2024
CVE-2024-33015
7.5 HIGH

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less …

Aug 5, 2024
CVE-2024-33014
7.5 HIGH

Transient DOS while parsing ESP IE from beacon/probe response frame.

Aug 5, 2024
CVE-2024-33013
7.5 HIGH

Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.

Aug 5, 2024
CVE-2024-33012
7.5 HIGH

Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.

Aug 5, 2024
CVE-2024-33011
7.5 HIGH

Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

Aug 5, 2024
CVE-2024-33010
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Aug 5, 2024
CVE-2024-23384
8.4 HIGH

Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.

Aug 5, 2024
CVE-2024-23383
8.4 HIGH

Memory corruption when kernel driver attempts to trigger hardware fences.

Aug 5, 2024
CVE-2024-23382
8.4 HIGH

Memory corruption while processing graphics kernel driver request to create DMA fence.

Aug 5, 2024
CVE-2024-23381
8.4 HIGH

Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.

Aug 5, 2024
CVE-2024-23357
6.2 MEDIUM

Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

Aug 5, 2024
CVE-2024-23356
7.8 HIGH

Memory corruption during session sign renewal request calls in HLOS.

Aug 5, 2024
CVE-2024-23355
7.8 HIGH

Memory corruption when keymaster operation imports a shared key.

Aug 5, 2024
CVE-2024-23353
7.5 HIGH

Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

Aug 5, 2024
CVE-2024-23352
7.5 HIGH

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

Aug 5, 2024
CVE-2024-23350
6.5 MEDIUM

Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is …

Aug 5, 2024
CVE-2024-21481
8.4 HIGH

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

Aug 5, 2024
CVE-2024-21479
7.5 HIGH

Transient DOS during music playback of ALAC content.

Aug 5, 2024
CVE-2024-21467
6.5 MEDIUM

Information disclosure while handling beacon probe frame during scan entry generation in client side.

Aug 5, 2024
CVE-2024-21459
6.5 MEDIUM

Information disclosure while handling beacon or probe response frame in STA.

Aug 5, 2024
CVE-2024-7409
7.5 HIGH

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when …

Aug 5, 2024
CVE-2024-7397

Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.

Aug 5, 2024
CVE-2024-7396

Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.

Aug 5, 2024
CVE-2024-7395

An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: …

Aug 5, 2024
CVE-2024-7383
7.4 HIGH

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD …

Aug 5, 2024
CVE-2024-6865

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 5, 2024
CVE-2024-6472
7.8 HIGH

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. …

Aug 5, 2024
CVE-2024-4607
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Aug 5, 2024
CVE-2024-2937
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Aug 5, 2024
CVE-2024-40096
3.3 LOW

The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.

Aug 5, 2024
CVE-2024-36448
7.3 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project …

Aug 5, 2024
CVE-2024-38856
9.8 CRITICAL KEV

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. …

Aug 5, 2024
CVE-2024-42447
9.8 CRITICAL

Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB …

Aug 5, 2024
CVE-2024-6710
5.4 MEDIUM

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to …

Aug 5, 2024
CVE-2024-6498
4.8 MEDIUM

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege …

Aug 5, 2024
CVE-2024-6270
4.8 MEDIUM

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Aug 5, 2024
CVE-2024-5081
6.1 MEDIUM

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Aug 5, 2024
CVE-2024-3636
5.4 MEDIUM

The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Aug 5, 2024
CVE-2024-2232
8.1 HIGH

The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

Aug 5, 2024
CVE-2024-6118
9.1 CRITICAL

A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials …

Aug 5, 2024
CVE-2024-6117
8.8 HIGH

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform …

Aug 5, 2024
CVE-2024-41889
9.8 CRITICAL

Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.

Aug 5, 2024
CVE-2024-41720
8.0 HIGH

Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the …

Aug 5, 2024
CVE-2024-39838
8.8 HIGH

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the …

Aug 5, 2024
CVE-2024-39713
8.6 HIGH

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

Aug 5, 2024
CVE-2024-7470
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7469
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of …

Aug 5, 2024
CVE-2024-7468
6.3 MEDIUM

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the …

Aug 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.