CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21466
6.5 MEDIUM

Information disclosure while parsing sub-IE length during new IE generation.

Jul 1, 2024
CVE-2024-21465
7.8 HIGH

Memory corruption while processing key blob passed by the user.

Jul 1, 2024
CVE-2024-21462
7.1 HIGH

Transient DOS while loading the TA ELF file.

Jul 1, 2024
CVE-2024-21461
8.4 HIGH

Memory corruption while performing finish HMAC operation when context is freed by keymaster.

Jul 1, 2024
CVE-2024-21460
7.1 HIGH

Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.

Jul 1, 2024
CVE-2024-21458
6.5 MEDIUM

Information disclosure while handling SA query action frame.

Jul 1, 2024
CVE-2024-21457
6.5 MEDIUM

INformation disclosure while handling Multi-link IE in beacon frame.

Jul 1, 2024
CVE-2024-21456
6.5 MEDIUM

Information Disclosure while parsing beacon frame in STA.

Jul 1, 2024
CVE-2023-43554
8.4 HIGH

Memory corruption while processing IOCTL handler in FastRPC.

Jul 1, 2024
CVE-2024-6050
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into …

Jul 1, 2024
CVE-2024-38953
6.1 MEDIUM

phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

Jul 1, 2024
CVE-2024-24749
7.5 HIGH

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed …

Jul 1, 2024
CVE-2024-6425
9.1 CRITICAL

Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" …

Jul 1, 2024
CVE-2024-6424
9.3 CRITICAL

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=<FILE|INTERNAL URL|IP/HOST" or "/api/Proxy/Get?userName=&password=&uri=<ARCHIVO|URL INTERNA|IP/HOST" to …

Jul 1, 2024
CVE-2024-6387
8.1 HIGH

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an …

Jul 1, 2024
CVE-2024-4007
8.8 HIGH

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Jul 1, 2024
CVE-2024-39853
6.5 MEDIUM

adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39018
6.3 MEDIUM

harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39017
9.8 CRITICAL

agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39016
8.1 HIGH

che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39015
9.8 CRITICAL

cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39014
9.8 CRITICAL

ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39013
9.8 CRITICAL

2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39008
10.0 CRITICAL

robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39003
7.3 HIGH

amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause …

Jul 1, 2024
CVE-2024-39002
6.3 MEDIUM

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39001
6.3 MEDIUM

ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39000
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38999
10.0 CRITICAL

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38998

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jul 1, 2024
CVE-2024-38997
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38996
9.8 CRITICAL

ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or …

Jul 1, 2024
CVE-2024-38994
7.3 HIGH

amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause …

Jul 1, 2024
CVE-2024-38993
9.8 CRITICAL

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38992
8.8 HIGH

airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38991
8.8 HIGH

akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38990
6.3 MEDIUM

Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38987
6.3 MEDIUM

aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39430
5.1 MEDIUM

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39429
5.1 MEDIUM

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39428
6.8 MEDIUM

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-39427
5.1 MEDIUM

In trusty service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jul 1, 2024
CVE-2024-0153
7.8 HIGH

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture …

Jul 1, 2024
CVE-2024-6130
4.8 MEDIUM

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jul 1, 2024
CVE-2024-4934
5.5 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in …

Jul 1, 2024
CVE-2024-3123
7.2 HIGH

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this …

Jul 1, 2024
CVE-2024-3122
4.9 MEDIUM

CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file …

Jul 1, 2024
CVE-2024-38480
4.0 MEDIUM

"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker …

Jul 1, 2024
CVE-2024-20081
6.7 MEDIUM

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jul 1, 2024
CVE-2024-20080
9.8 CRITICAL

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no …

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.