CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25646
7.7 HIGH

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation …

Apr 9, 2024
CVE-2024-23084
7.5 HIGH

Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-27632
8.8 HIGH

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

Apr 8, 2024
CVE-2024-0082
8.2 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the …

Apr 8, 2024
CVE-2024-27630
7.5 HIGH

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file …

Apr 8, 2024
CVE-2024-24279
8.8 HIGH

An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower …

Apr 8, 2024
CVE-2024-23085
7.5 HIGH

Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-28270
8.1 HIGH

An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.

Apr 8, 2024
CVE-2023-7164
7.5 HIGH

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's …

Apr 8, 2024
CVE-2024-31442
8.8 HIGH

Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being …

Apr 8, 2024
CVE-2024-28732
7.5 HIGH

An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite …

Apr 8, 2024
CVE-2024-31817
7.5 HIGH

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

Apr 8, 2024
CVE-2024-31816
7.5 HIGH

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

Apr 8, 2024
CVE-2024-31814
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

Apr 8, 2024
CVE-2024-31813
8.4 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

Apr 8, 2024
CVE-2024-31811
8.0 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

Apr 8, 2024
CVE-2024-31809
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.

Apr 8, 2024
CVE-2024-31808
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

Apr 8, 2024
CVE-2024-2834
8.7 HIGH

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

Apr 8, 2024
CVE-2024-28066
8.8 HIGH

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

Apr 8, 2024
CVE-2024-3439
7.3 HIGH

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. …

Apr 8, 2024
CVE-2024-26574
7.8 HIGH

Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe

Apr 8, 2024
CVE-2024-3438
7.3 HIGH

A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The …

Apr 8, 2024
CVE-2024-27897
7.5 HIGH

Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2024-27896
7.5 HIGH

Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

Apr 8, 2024
CVE-2024-27895
7.5 HIGH

Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

Apr 8, 2024
CVE-2023-52386
7.5 HIGH

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52553
7.4 HIGH

Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52552
7.5 HIGH

Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52550
7.5 HIGH

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52549
7.5 HIGH

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52546
7.5 HIGH

Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52545
7.5 HIGH

Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52541
7.5 HIGH

Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52540
7.5 HIGH

Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52539
7.5 HIGH

Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52537
7.5 HIGH

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52388
7.5 HIGH

Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52359
7.5 HIGH

Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52351
7.8 HIGH

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52342
7.5 HIGH

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52341
7.5 HIGH

In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no …

Apr 8, 2024
CVE-2024-28744
8.8 HIGH

The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker …

Apr 8, 2024
CVE-2024-3437
7.3 HIGH

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Apr 8, 2024
CVE-2020-36829
7.5 HIGH

The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. …

Apr 8, 2024
CVE-2024-31292
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a …

Apr 7, 2024
CVE-2024-31288
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.

Apr 7, 2024
CVE-2024-31277
8.7 HIGH

Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.

Apr 7, 2024
CVE-2024-31260
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WisdmLabs Edwiser Bridge.This issue affects Edwiser Bridge: from n/a through 3.0.2.

Apr 7, 2024
CVE-2024-31256
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebinarPress allows Reflected XSS.This issue affects WebinarPress: from n/a through 1.33.10.

Apr 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.