CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42059
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG …

Sep 3, 2024
CVE-2024-42058
7.5 HIGH

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42057
8.1 HIGH

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from …

Sep 3, 2024
CVE-2024-1621
7.5 HIGH

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the …

Sep 2, 2024
CVE-2024-6921
7.5 HIGH

Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-45388
7.5 HIGH

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new …

Sep 2, 2024
CVE-2024-45311
7.5 HIGH

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, …

Sep 2, 2024
CVE-2024-42471
7.3 HIGH

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when …

Sep 2, 2024
CVE-2024-28100
8.9 HIGH

eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a …

Sep 2, 2024
CVE-2024-8004
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Sep 2, 2024
CVE-2024-7939
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-7938
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Sep 2, 2024
CVE-2024-7932
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-5148
7.5 HIGH

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a …

Sep 2, 2024
CVE-2024-38402
7.8 HIGH

Memory corruption while processing IOCTL call for getting group info.

Sep 2, 2024
CVE-2024-38401
7.8 HIGH

Memory corruption while processing concurrent IOCTL calls.

Sep 2, 2024
CVE-2024-33060
8.4 HIGH

Memory corruption when two threads try to map and unmap a single node simultaneously.

Sep 2, 2024
CVE-2024-33057
7.5 HIGH

Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.

Sep 2, 2024
CVE-2024-33054
7.8 HIGH

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

Sep 2, 2024
CVE-2024-33052
7.8 HIGH

Memory corruption when user provides data for FM HCI command control operations.

Sep 2, 2024
CVE-2024-33051
7.5 HIGH

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

Sep 2, 2024
CVE-2024-33050
7.5 HIGH

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

Sep 2, 2024
CVE-2024-33048
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

Sep 2, 2024
CVE-2024-33047
8.4 HIGH

Memory corruption when the captureRead QDCM command is invoked from user-space.

Sep 2, 2024
CVE-2024-33045
8.4 HIGH

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Sep 2, 2024
CVE-2024-33042
7.8 HIGH

Memory corruption when Alternative Frequency offset value is set to 255.

Sep 2, 2024
CVE-2024-33038
7.8 HIGH

Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

Sep 2, 2024
CVE-2024-33035
8.4 HIGH

Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

Sep 2, 2024
CVE-2024-23365
8.4 HIGH

Memory corruption while releasing shared resources in MinkSocket listener thread.

Sep 2, 2024
CVE-2024-23364
7.5 HIGH

Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air …

Sep 2, 2024
CVE-2024-23362
7.1 HIGH

Cryptographic issue while parsing RSA keys in COBR format.

Sep 2, 2024
CVE-2024-23359
8.2 HIGH

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

Sep 2, 2024
CVE-2024-23358
7.5 HIGH

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

Sep 2, 2024
CVE-2024-7871
8.8 HIGH

SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43776
8.8 HIGH

SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43775
8.8 HIGH

SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via …

Sep 2, 2024
CVE-2024-43774
8.8 HIGH

SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands …

Sep 2, 2024
CVE-2024-41160
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-41157
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-39816
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024
CVE-2024-38386
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024
CVE-2024-20089
7.5 HIGH

In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional …

Sep 2, 2024
CVE-2024-8368
7.3 HIGH

A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 1, 2024
CVE-2024-7717
8.8 HIGH

The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 …

Aug 31, 2024
CVE-2024-44945
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN …

Aug 31, 2024
CVE-2024-7435
8.8 HIGH

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This …

Aug 31, 2024
CVE-2024-39747
8.1 HIGH

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Aug 31, 2024
CVE-2024-6586
7.3 HIGH

Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements …

Aug 30, 2024
CVE-2024-38868
7.6 HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15

Aug 30, 2024
CVE-2024-6204
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

Aug 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.