CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6264
6.4 MEDIUM

The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, …

Jul 2, 2024
CVE-2024-6099
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This …

Jul 2, 2024
CVE-2024-6088
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function …

Jul 2, 2024
CVE-2024-4268
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, …

Jul 2, 2024
CVE-2024-6012
4.3 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' …

Jul 2, 2024
CVE-2024-6011
4.4 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 …

Jul 2, 2024
CVE-2024-34601
5.9 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.

Jul 2, 2024
CVE-2024-34600
4.4 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.

Jul 2, 2024
CVE-2024-34599
4.0 MEDIUM

Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.

Jul 2, 2024
CVE-2024-34597
4.4 MEDIUM

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User …

Jul 2, 2024
CVE-2024-34596
5.9 MEDIUM

Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

Jul 2, 2024
CVE-2024-34595
7.8 HIGH

Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-34594
5.5 MEDIUM

Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

Jul 2, 2024
CVE-2024-34593
7.5 HIGH

Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with …

Jul 2, 2024
CVE-2024-34592
5.3 MEDIUM

Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. …

Jul 2, 2024
CVE-2024-34591
5.3 MEDIUM

Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger …

Jul 2, 2024
CVE-2024-34590
5.3 MEDIUM

Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary …

Jul 2, 2024
CVE-2024-34589
5.3 MEDIUM

Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. …

Jul 2, 2024
CVE-2024-34588
5.3 MEDIUM

Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User …

Jul 2, 2024
CVE-2024-34587
7.5 HIGH

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code …

Jul 2, 2024
CVE-2024-34586
5.9 MEDIUM

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

Jul 2, 2024
CVE-2024-34585
7.8 HIGH

Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-34583
4.0 MEDIUM

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

Jul 2, 2024
CVE-2024-20901
5.9 MEDIUM

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

Jul 2, 2024
CVE-2024-20900
4.0 MEDIUM

Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

Jul 2, 2024
CVE-2024-20899
4.0 MEDIUM

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive …

Jul 2, 2024
CVE-2024-20898
4.0 MEDIUM

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Jul 2, 2024
CVE-2024-20897
4.0 MEDIUM

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive …

Jul 2, 2024
CVE-2024-20896
5.5 MEDIUM

Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Jul 2, 2024
CVE-2024-20895
7.7 HIGH

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

Jul 2, 2024
CVE-2024-20894
4.3 MEDIUM

Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction …

Jul 2, 2024
CVE-2024-20893
6.1 MEDIUM

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

Jul 2, 2024
CVE-2024-20892
6.5 MEDIUM

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering …

Jul 2, 2024
CVE-2024-20891
7.8 HIGH

Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-20890
5.3 MEDIUM

Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

Jul 2, 2024
CVE-2024-20889
5.9 MEDIUM

Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

Jul 2, 2024
CVE-2024-20888
7.8 HIGH

Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this …

Jul 2, 2024
CVE-2024-5260
6.4 MEDIUM

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to …

Jul 2, 2024
CVE-2024-4836
7.5 HIGH

Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by …

Jul 2, 2024
CVE-2024-37185
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-37077
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-37030
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

Jul 2, 2024
CVE-2024-36278
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

Jul 2, 2024
CVE-2024-36260
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-36243
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

Jul 2, 2024
CVE-2024-31071
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

Jul 2, 2024
CVE-2024-5545
5.3 MEDIUM

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jul 2, 2024
CVE-2024-5544
6.1 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 …

Jul 2, 2024
CVE-2024-5504
6.4 MEDIUM

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline …

Jul 2, 2024
CVE-2024-3513
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions …

Jul 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.