CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31255
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts allows Reflected XSS.This issue affects ELEX …

Apr 7, 2024
CVE-2024-31241
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a …

Apr 7, 2024
CVE-2024-31234
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam REHub Framework.This issue affects REHub Framework: from n/a before 19.6.2.

Apr 7, 2024
CVE-2024-31233
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam Rehub.This issue affects Rehub: from n/a through 19.6.1.

Apr 7, 2024
CVE-2024-30418
7.5 HIGH

Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2024-30417
7.5 HIGH

Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2024
CVE-2024-30416
7.5 HIGH

Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2023-52716
7.5 HIGH

Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2023-52715
7.5 HIGH

The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.

Apr 7, 2024
CVE-2023-52714
7.5 HIGH

Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2024
CVE-2023-52713
7.7 HIGH

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Apr 7, 2024
CVE-2024-30414
7.5 HIGH

Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 7, 2024
CVE-2024-30413
7.5 HIGH

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2024-3413
7.3 HIGH

A vulnerability has been found in SourceCodester Human Resource Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file initialize/login_process.php. …

Apr 6, 2024
CVE-2024-28741
8.8 HIGH

Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

Apr 6, 2024
CVE-2024-27620
7.5 HIGH

An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

Apr 6, 2024
CVE-2024-3159
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML …

Apr 6, 2024
CVE-2024-3158
8.8 HIGH

Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 6, 2024
CVE-2024-3156
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Apr 6, 2024
CVE-2024-3376
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file config.php. The …

Apr 6, 2024
CVE-2024-24746
7.5 HIGH

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial …

Apr 6, 2024
CVE-2024-22328
7.5 HIGH

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

Apr 6, 2024
CVE-2024-3363
7.3 HIGH

A vulnerability was found in SourceCodester Online Library System 1.0. It has been classified as critical. This affects an unknown part of the file admin/borrowed/index.php. …

Apr 6, 2024
CVE-2024-3362
7.3 HIGH

A vulnerability was found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Apr 6, 2024
CVE-2024-3361
7.3 HIGH

A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Apr 6, 2024
CVE-2024-3360
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Online Library System 1.0. Affected is an unknown function of the file admin/books/index.php. The …

Apr 6, 2024
CVE-2024-3359
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file …

Apr 6, 2024
CVE-2024-1385
7.1 HIGH

The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() …

Apr 6, 2024
CVE-2024-3356
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been rated as critical. Affected by this issue is some …

Apr 5, 2024
CVE-2024-3355
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an …

Apr 5, 2024
CVE-2024-30977
7.8 HIGH

An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.

Apr 5, 2024
CVE-2024-27912
7.5 HIGH

A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted …

Apr 5, 2024
CVE-2024-27911
7.5 HIGH

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

Apr 5, 2024
CVE-2024-3354
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been classified as critical. Affected is an unknown function of …

Apr 5, 2024
CVE-2024-3353
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the …

Apr 5, 2024
CVE-2024-29757
7.3 HIGH

there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges …

Apr 5, 2024
CVE-2024-29753
7.7 HIGH

In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29752
7.8 HIGH

In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29749
8.4 HIGH

In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29748
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Apr 5, 2024
CVE-2024-29746
8.4 HIGH

In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Apr 5, 2024
CVE-2024-29743
7.7 HIGH

In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29741
7.8 HIGH

In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29740
7.4 HIGH

In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-3352
7.3 HIGH

A vulnerability has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Apr 5, 2024
CVE-2024-0081
8.6 HIGH

NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful …

Apr 5, 2024
CVE-2024-3351
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the …

Apr 5, 2024
CVE-2024-3350
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this issue is some …

Apr 5, 2024
CVE-2024-31851
8.6 HIGH

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an …

Apr 5, 2024
CVE-2024-31850
8.6 HIGH

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an …

Apr 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.