CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29781
7.5 HIGH

In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with …

Jun 13, 2024
CVE-2024-29780
5.5 MEDIUM

In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local information disclosure with no …

Jun 13, 2024
CVE-2024-29778
4.7 MEDIUM

In ProtocolPsDedicatedBearInfoAdapter::processQosSession of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024
CVE-2024-5952
6.5 MEDIUM

Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 …

Jun 13, 2024
CVE-2024-5951
6.5 MEDIUM

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics …

Jun 13, 2024
CVE-2024-5950
8.8 HIGH

Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …

Jun 13, 2024
CVE-2024-5949
6.5 MEDIUM

Deep Sea Electronics DSE855 Multipart Boundary Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Deep …

Jun 13, 2024
CVE-2024-5948
8.8 HIGH

Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Jun 13, 2024
CVE-2024-5947
6.5 MEDIUM

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep …

Jun 13, 2024
CVE-2024-5924
8.8 HIGH

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User …

Jun 13, 2024
CVE-2024-4696
7.5 HIGH

A privilege escalation vulnerability was reported in Lenovo Service Bridge prior to version 5.0.2.17 that could allow operating system commands to be executed if a …

Jun 13, 2024
CVE-2024-38313
4.3 MEDIUM

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address …

Jun 13, 2024
CVE-2024-38312
6.5 MEDIUM

When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination …

Jun 13, 2024
CVE-2024-38083
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 13, 2024
CVE-2024-30058
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 13, 2024
CVE-2024-30057
5.4 MEDIUM

Microsoft Edge for iOS Spoofing Vulnerability

Jun 13, 2024
CVE-2024-37635
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

Jun 13, 2024
CVE-2024-37634
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

Jun 13, 2024
CVE-2024-37633
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg

Jun 13, 2024
CVE-2024-37632
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

Jun 13, 2024
CVE-2024-37631
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.

Jun 13, 2024
CVE-2024-36589
4.3 MEDIUM

An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.

Jun 13, 2024
CVE-2024-36588
6.5 MEDIUM

An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.

Jun 13, 2024
CVE-2024-36587
7.8 HIGH

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

Jun 13, 2024
CVE-2024-36586
8.8 HIGH

An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.

Jun 13, 2024
CVE-2024-38285

Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.

Jun 13, 2024
CVE-2024-38284

Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.

Jun 13, 2024
CVE-2024-38283

Sensitive customer information is stored in the device without encryption.

Jun 13, 2024
CVE-2024-38282

Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes to be made to the operations or …

Jun 13, 2024
CVE-2024-37630
8.8 HIGH

D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

Jun 13, 2024
CVE-2024-37029
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 13, 2024
CVE-2024-37022
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipulate memory, resulting in execution of arbitrary code.

Jun 13, 2024
CVE-2024-36760
7.5 HIGH

A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : …

Jun 13, 2024
CVE-2024-38281
9.8 CRITICAL

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

Jun 13, 2024
CVE-2024-38280
4.6 MEDIUM

An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data …

Jun 13, 2024
CVE-2024-38279
4.6 MEDIUM

The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system …

Jun 13, 2024
CVE-2024-37280
4.9 MEDIUM

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting …

Jun 13, 2024
CVE-2024-37279
4.3 MEDIUM

A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the …

Jun 13, 2024
CVE-2024-35326

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jun 13, 2024
CVE-2024-35325

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jun 13, 2024
CVE-2024-32504
8.4 HIGH

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, …

Jun 13, 2024
CVE-2024-31956
8.4 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an …

Jun 13, 2024
CVE-2024-37877
5.5 MEDIUM

UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occurs in function readOctetString in src/utils/octet_view.cpp …

Jun 13, 2024
CVE-2024-37307
7.9 HIGH

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the …

Jun 13, 2024
CVE-2024-35328

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jun 13, 2024
CVE-2024-29169
5.4 MEDIUM

Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker …

Jun 13, 2024
CVE-2024-22441
9.8 CRITICAL

HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

Jun 13, 2024
CVE-2023-35860
5.3 MEDIUM

A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter …

Jun 13, 2024
CVE-2023-35859
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts …

Jun 13, 2024
CVE-2023-35858
5.3 MEDIUM

XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.