CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7879
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors …

Nov 6, 2024
CVE-2024-49409
6.4 MEDIUM

Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege …

Nov 6, 2024
CVE-2024-49408
6.4 MEDIUM

Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required …

Nov 6, 2024
CVE-2024-49407
4.6 MEDIUM

Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.

Nov 6, 2024
CVE-2024-49406
6.7 MEDIUM

Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering …

Nov 6, 2024
CVE-2024-49405
5.3 MEDIUM

Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario.

Nov 6, 2024
CVE-2024-49404
5.5 MEDIUM

Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows physical …

Nov 6, 2024
CVE-2024-49403
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.

Nov 6, 2024
CVE-2024-49402
4.6 MEDIUM

Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.

Nov 6, 2024
CVE-2024-49401
5.1 MEDIUM

Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.

Nov 6, 2024
CVE-2024-34681
6.6 MEDIUM

Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.

Nov 6, 2024
CVE-2024-34680
4.0 MEDIUM

Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.

Nov 6, 2024
CVE-2024-34679
4.0 MEDIUM

Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

Nov 6, 2024
CVE-2024-34678
5.9 MEDIUM

Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.

Nov 6, 2024
CVE-2024-34677
4.0 MEDIUM

Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

Nov 6, 2024
CVE-2024-34676
4.4 MEDIUM

Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required …

Nov 6, 2024
CVE-2024-34674
4.6 MEDIUM

Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

Nov 6, 2024
CVE-2024-34673
4.1 MEDIUM

Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

Nov 6, 2024
CVE-2024-10647
6.1 MEDIUM

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the …

Nov 6, 2024
CVE-2024-47464
6.8 MEDIUM

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a …

Nov 5, 2024
CVE-2024-10084
4.3 MEDIUM

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 …

Nov 5, 2024
CVE-2024-51752
5.5 MEDIUM

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are …

Nov 5, 2024
CVE-2024-51740
4.3 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, …

Nov 5, 2024
CVE-2024-51493
5.3 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that …

Nov 5, 2024
CVE-2024-50335
4.9 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site …

Nov 5, 2024
CVE-2024-50333
6.6 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserLabel::addLabels() function …

Nov 5, 2024
CVE-2024-49773
5.3 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled …

Nov 5, 2024
CVE-2024-49377
5.5 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog …

Nov 5, 2024
CVE-2024-0134
4.1 MEDIUM

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of …

Nov 5, 2024
CVE-2024-50138
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Use raw_spinlock_t in ringbuf The function __bpf_ringbuf_reserve is invoked from a tracepoint, which disables …

Nov 5, 2024
CVE-2024-50137
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: reset: starfive: jh71x0: Fix accessing the empty member on JH7110 SoC data->asserted will be NULL …

Nov 5, 2024
CVE-2024-50136
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt …

Nov 5, 2024
CVE-2024-50135
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev->online_queues field, therefore nvme_pci_update_nr_queues() …

Nov 5, 2024
CVE-2024-50134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA Replace the fake VLA …

Nov 5, 2024
CVE-2024-50133
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Don't crash in stack_top() for tasks without vDSO Not all tasks have a vDSO …

Nov 5, 2024
CVE-2024-50132
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix MAX_TRACE_ARGS limit handling When creating a trace_probe we would set nr_args prior to …

Nov 5, 2024
CVE-2024-50122
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Hold rescan lock while adding devices during host probe Since adding the PCI power …

Nov 5, 2024
CVE-2024-50120
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: Handle kstrdup failures for passwords In smb3_reconfigure(), after duplicating ctx->password and ctx->password2 with …

Nov 5, 2024
CVE-2024-50119
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: fix warning when destroy 'cifs_io_request_pool' There's a issue as follows: WARNING: CPU: 1 PID: …

Nov 5, 2024
CVE-2024-50118
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject ro->rw reconfiguration if there are hard ro requirements [BUG] Syzbot reports the following …

Nov 5, 2024
CVE-2024-50117
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd: Guard against bad data for ATIF ACPI method If a BIOS provides bad data …

Nov 5, 2024
CVE-2024-50116
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug due to missing clearing of buffer delay flag Syzbot reported that …

Nov 5, 2024
CVE-2024-50113
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix invalid port index for parent device In a commit 24b7f8e5cd65 ("firewire: core: …

Nov 5, 2024
CVE-2024-50111
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable IRQ if do_ale() triggered in irq-enabled context Unaligned access exception can be triggered …

Nov 5, 2024
CVE-2024-50110
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix one more kernel-infoleak in algo dumping During fuzz testing, the following issue was …

Nov 5, 2024
CVE-2024-50109
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null ptr dereference in raid10_size() In raid10_run() if raid10_set_queue_limits() succeed, the return value …

Nov 5, 2024
CVE-2024-50108
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too Stuart Hayhurst has found that both at …

Nov 5, 2024
CVE-2024-50107
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid addresses Commit 50c6dbdfd16e ("x86/ioremap: Improve iounmap() address …

Nov 5, 2024
CVE-2024-50105
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: sc7280: Fix missing Soundwire runtime stream alloc Commit 15c7fab0e047 ("ASoC: qcom: Move Soundwire …

Nov 5, 2024
CVE-2024-50104
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: sdm845: add missing soundwire runtime stream alloc During the migration of Soundwire runtime …

Nov 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.