CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-34956
7.8 HIGH

Foxit PDF Editor Underline Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34955
7.8 HIGH

Foxit PDF Editor Stamp Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34954
7.8 HIGH

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34953
7.8 HIGH

Foxit PDF Reader Annotation Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

May 7, 2024
CVE-2021-34952
7.8 HIGH

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34951
3.3 LOW

Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

May 7, 2024
CVE-2021-34950
7.8 HIGH

Foxit PDF Reader Annotation Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34949
5.5 MEDIUM

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

May 7, 2024
CVE-2021-34948
7.8 HIGH

Foxit PDF Reader Square Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

May 7, 2024
CVE-2021-34947
8.8 HIGH

NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. …

May 7, 2024
CVE-2024-23551
6.5 MEDIUM

Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a …

May 7, 2024
CVE-2024-4030
7.1 HIGH

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, …

May 7, 2024
CVE-2024-34346
8.4 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly weakened by allowing file read/write access to privileged …

May 7, 2024
CVE-2024-27273
8.1 HIGH

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with …

May 7, 2024
CVE-2024-23713
7.8 HIGH

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of …

May 7, 2024
CVE-2024-23712
5.5 MEDIUM

In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local …

May 7, 2024
CVE-2024-23710
7.8 HIGH

In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. …

May 7, 2024
CVE-2024-23709
6.5 MEDIUM

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with …

May 7, 2024
CVE-2024-23708
7.8 HIGH

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could …

May 7, 2024
CVE-2024-23707
7.8 HIGH

In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional …

May 7, 2024
CVE-2024-23706
7.8 HIGH

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of …

May 7, 2024
CVE-2024-23705
7.8 HIGH

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation …

May 7, 2024
CVE-2024-23704
7.8 HIGH

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local …

May 7, 2024
CVE-2024-0043
7.8 HIGH

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the …

May 7, 2024
CVE-2024-0042
7.8 HIGH

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass …

May 7, 2024
CVE-2024-0027
5.5 MEDIUM

In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial …

May 7, 2024
CVE-2024-0026
5.5 MEDIUM

In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service …

May 7, 2024
CVE-2024-0025
7.8 HIGH

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with …

May 7, 2024
CVE-2024-0024
7.8 HIGH

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to …

May 7, 2024
CVE-2024-0022
5.5 MEDIUM

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local …

May 7, 2024
CVE-2023-40694
6.2 MEDIUM

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force …

May 7, 2024
CVE-2024-4559
6.5 MEDIUM

Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 7, 2024
CVE-2024-4558
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 7, 2024
CVE-2024-34315
7.5 HIGH

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers …

May 7, 2024
CVE-2024-34314
4.9 MEDIUM

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. This vulnerability allows attackers …

May 7, 2024
CVE-2024-25514
9.4 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx.

May 7, 2024
CVE-2024-25513
7.8 HIGH

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.

May 7, 2024
CVE-2024-25511
9.4 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.

May 7, 2024
CVE-2024-25510
9.8 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx.

May 7, 2024
CVE-2024-25509
9.4 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file_download.aspx.

May 7, 2024
CVE-2024-34517
6.5 MEDIUM

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

May 7, 2024
CVE-2024-34397
5.2 MEDIUM

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted …

May 7, 2024
CVE-2024-25512
8.1 HIGH

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.aspx.

May 7, 2024
CVE-2024-25508
9.8 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.

May 7, 2024
CVE-2024-25507
9.4 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.aspx.

May 7, 2024
CVE-2023-42757
4.2 MEDIUM

Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new …

May 7, 2024
CVE-2024-33860
6.5 MEDIUM

An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System …

May 7, 2024
CVE-2024-33859
6.1 MEDIUM

An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.

May 7, 2024
CVE-2024-33164
9.8 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.

May 7, 2024
CVE-2024-33161
5.3 MEDIUM

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.

May 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.