CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34446
7.5 HIGH

Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and …

May 3, 2024
CVE-2024-33844
7.5 HIGH

The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between …

May 3, 2024
CVE-2024-29417
8.4 HIGH

Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.

May 3, 2024
CVE-2022-48694
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix drain SQ hang with no completion SW generated completions for outstanding WRs posted …

May 3, 2024
CVE-2022-48693
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs In brcmstb_pm_probe(), there are two …

May 3, 2024
CVE-2022-48692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Set scmnd->result only when scmnd is not NULL This change fixes the following kernel …

May 3, 2024
CVE-2022-48691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clean up hook list when offload flags check fails splice back the hook …

May 3, 2024
CVE-2022-48689
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp: TX zerocopy should not sense pfmemalloc status We got a recent syzbot report [1] …

May 3, 2024
CVE-2022-48688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix kernel crash during module removal The driver incorrectly frees client instance and subsequent …

May 3, 2024
CVE-2022-48687
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix out-of-bounds read when setting HMAC data. The SRv6 layer allows defining HMAC …

May 3, 2024
CVE-2022-48686
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop …

May 3, 2024
CVE-2022-48675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix a nested dead lock as part of ODP flow Fix a nested dead …

May 3, 2024
CVE-2022-48674
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: erofs: fix pcluster use-after-free on UP platforms During stress testing with CONFIG_SMP disabled, KASAN reports …

May 3, 2024
CVE-2022-48673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in link clear After modifying the QP to …

May 3, 2024
CVE-2022-48672
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") …

May 3, 2024
CVE-2022-48671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for …

May 3, 2024
CVE-2022-48670
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which …

May 3, 2024
CVE-2024-3109
6.3 MEDIUM

A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker …

May 3, 2024
CVE-2024-3108
5.5 MEDIUM

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device …

May 3, 2024
CVE-2024-1395
6.7 MEDIUM

Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing …

May 3, 2024
CVE-2024-1067
7.4 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

May 3, 2024
CVE-2023-6363
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

May 3, 2024
CVE-2023-41830
6.5 MEDIUM

An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.

May 3, 2024
CVE-2023-41828
4.4 MEDIUM

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.

May 3, 2024
CVE-2023-41826
5.1 MEDIUM

A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without …

May 3, 2024
CVE-2023-41825
2.8 LOW

A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.

May 3, 2024
CVE-2023-41824
2.8 LOW

An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and …

May 3, 2024
CVE-2023-41823
4.4 MEDIUM

An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.

May 3, 2024
CVE-2023-41822
4.8 MEDIUM

An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.

May 3, 2024
CVE-2023-41821
5.0 MEDIUM

A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.

May 3, 2024
CVE-2023-41820
5.0 MEDIUM

An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio …

May 3, 2024
CVE-2023-41819
6.1 MEDIUM

A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.

May 3, 2024
CVE-2023-41818
5.0 MEDIUM

An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker …

May 3, 2024
CVE-2023-41817
2.8 LOW

An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.

May 3, 2024
CVE-2023-41816
5.0 MEDIUM

An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.

May 3, 2024
CVE-2024-33787
8.2 HIGH

Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerability via the tuser_Number parameter at search_user.aspx.

May 3, 2024
CVE-2024-33786
9.8 CRITICAL

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

May 3, 2024
CVE-2024-2410
7.6 HIGH

The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken …

May 3, 2024
CVE-2024-4466
9.8 CRITICAL

SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to send a specially crafted SQL query to the pass parameter …

May 3, 2024
CVE-2024-4461
7.8 HIGH

Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could allow an unauthorized local user to inject arbitrary …

May 3, 2024
CVE-2024-34073
7.8 HIGH

sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for …

May 3, 2024
CVE-2024-34072
7.8 HIGH

sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted …

May 3, 2024
CVE-2024-34063
2.5 LOW

vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes …

May 3, 2024
CVE-2024-34062
4.8 MEDIUM

tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, …

May 3, 2024
CVE-2024-32986
9.6 CRITICAL

PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such …

May 3, 2024
CVE-2024-33937
4.3 MEDIUM

Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.

May 3, 2024
CVE-2024-33931
6.5 MEDIUM

Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.

May 3, 2024
CVE-2024-33929
5.3 MEDIUM

Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

May 3, 2024
CVE-2024-33925
4.3 MEDIUM

Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

May 3, 2024
CVE-2024-33923
6.3 MEDIUM

Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.

May 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.