CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52438
8.8 HIGH

Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2.

Nov 20, 2024
CVE-2024-52437
8.8 HIGH

Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Privilege Escalation.This issue affects Banner System: from n/a through <= 1.0.0.

Nov 20, 2024
CVE-2024-45690
7.5 HIGH

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

Nov 20, 2024
CVE-2024-10382
7.5 HIGH

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction of arbitrary java classes. This …

Nov 20, 2024
CVE-2024-11494
7.5 HIGH

**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device …

Nov 20, 2024
CVE-2024-48895
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If …

Nov 20, 2024
CVE-2024-10899
7.3 HIGH

The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is …

Nov 20, 2024
CVE-2024-10855
8.1 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of …

Nov 20, 2024
CVE-2024-44308
8.8 HIGH KEV

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS …

Nov 20, 2024
CVE-2024-44307
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute …

Nov 20, 2024
CVE-2024-44306
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute …

Nov 20, 2024
CVE-2018-9466
8.8 HIGH

In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged …

Nov 19, 2024
CVE-2018-9456
7.5 HIGH

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of …

Nov 19, 2024
CVE-2024-52595
7.7 HIGH

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching …

Nov 19, 2024
CVE-2018-9433
8.8 HIGH

In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional …

Nov 19, 2024
CVE-2018-9432
7.8 HIGH

In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to local escalation of privilege due to hiding and bypassing …

Nov 19, 2024
CVE-2018-9428
7.8 HIGH

In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code …

Nov 19, 2024
CVE-2018-9424
7.8 HIGH

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Nov 19, 2024
CVE-2018-9419
7.5 HIGH

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 19, 2024
CVE-2018-9417
7.8 HIGH

In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no …

Nov 19, 2024
CVE-2018-9411
8.8 HIGH

In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with …

Nov 19, 2024
CVE-2018-9365
8.8 HIGH

In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead …

Nov 19, 2024
CVE-2024-52360
7.6 HIGH

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow …

Nov 19, 2024
CVE-2024-45419
8.1 HIGH

Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.

Nov 19, 2024
CVE-2024-11395
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 19, 2024
CVE-2018-9409
7.8 HIGH

In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Nov 19, 2024
CVE-2018-9372
7.8 HIGH

In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation …

Nov 19, 2024
CVE-2018-9370
7.3 HIGH

In download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounds check. This …

Nov 19, 2024
CVE-2018-9369
7.3 HIGH

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution …

Nov 19, 2024
CVE-2018-9368
7.8 HIGH

In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This could lead to local …

Nov 19, 2024
CVE-2018-9367
7.8 HIGH

In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Nov 19, 2024
CVE-2018-9366
7.8 HIGH

In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to …

Nov 19, 2024
CVE-2018-9364
7.5 HIGH

In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User …

Nov 19, 2024
CVE-2024-51503
8.0 HIGH

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute …

Nov 19, 2024
CVE-2024-21697
8.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE …

Nov 19, 2024
CVE-2018-9344
7.8 HIGH

In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with …

Nov 19, 2024
CVE-2018-9341
7.8 HIGH

In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution …

Nov 19, 2024
CVE-2018-9339
7.8 HIGH

In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege …

Nov 19, 2024
CVE-2024-53082
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key_length check in virtnet_probe() to avoid possible out of bound …

Nov 19, 2024
CVE-2024-53068
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier() The scmi_dev->name is released prematurely in __scmi_device_destroy(), which causes …

Nov 19, 2024
CVE-2024-53062
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mgb4: protect driver against spectre Frequency range is set from sysfs via frequency_range_store(), being …

Nov 19, 2024
CVE-2024-53061
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: s5p-jpeg: prevent buffer overflows The current logic allows word to be less than 2. …

Nov 19, 2024
CVE-2024-53059
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd() 1. The size of the response packet …

Nov 19, 2024
CVE-2024-53057
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT In qdisc_tree_reduce_backlog, Qdiscs with major handle ffff: are assumed to …

Nov 19, 2024
CVE-2024-48992
7.8 HIGH

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with …

Nov 19, 2024
CVE-2024-48991
7.8 HIGH

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into …

Nov 19, 2024
CVE-2024-48990
7.8 HIGH

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with …

Nov 19, 2024
CVE-2024-11003
7.8 HIGH

Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to …

Nov 19, 2024
CVE-2023-21270
7.8 HIGH

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared …

Nov 19, 2024
CVE-2018-9338
7.8 HIGH

In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Nov 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.