CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30339
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30338
7.8 HIGH

Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Apr 2, 2024
CVE-2024-30337
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30336
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-31109
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a …

Apr 2, 2024
CVE-2024-31105
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.

Apr 2, 2024
CVE-2024-30809
7.5 HIGH

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-30807
7.5 HIGH

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by …

Apr 2, 2024
CVE-2024-30335
7.1 HIGH

Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

Apr 2, 2024
CVE-2024-28287
7.3 HIGH

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted …

Apr 2, 2024
CVE-2024-22248
7.1 HIGH

VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to …

Apr 2, 2024
CVE-2024-22246
7.4 HIGH

VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router …

Apr 2, 2024
CVE-2024-30248
7.7 HIGH

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As …

Apr 2, 2024
CVE-2024-30965
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.

Apr 2, 2024
CVE-2024-29514
8.8 HIGH

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

Apr 2, 2024
CVE-2024-29949
7.2 HIGH

There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.

Apr 2, 2024
CVE-2024-31005
8.1 HIGH

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

Apr 2, 2024
CVE-2024-31003
8.8 HIGH

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

Apr 2, 2024
CVE-2024-28226
8.1 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

Apr 2, 2024
CVE-2024-26674
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups During memory error injection test on kernels >= …

Apr 2, 2024
CVE-2024-26673
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - Disallow families …

Apr 2, 2024
CVE-2024-26672
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c:377 amdgpu_mca_smu_get_mca_entry() …

Apr 2, 2024
CVE-2024-26669
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: Fix chain template offload When a qdisc is deleted from a net device …

Apr 2, 2024
CVE-2024-26666
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix RCU use in TDLS fast-xmit This looks up the link under RCU …

Apr 2, 2024
CVE-2024-26665
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error …

Apr 2, 2024
CVE-2024-26664
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access Fix a bug that pdata->cpu_map[] is set before out-of-bounds …

Apr 2, 2024
CVE-2024-22092
7.7 HIGH

in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.

Apr 2, 2024
CVE-2024-25187
8.6 HIGH

Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html.

Apr 2, 2024
CVE-2024-20849
7.3 HIGH

Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.

Apr 2, 2024
CVE-2024-20845
8.4 HIGH

Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

Apr 2, 2024
CVE-2024-20844
8.4 HIGH

Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

Apr 2, 2024
CVE-2024-3137
7.1 HIGH

Improper Privilege Management in uvdesk/community-skeleton

Apr 2, 2024
CVE-2024-27327
7.8 HIGH

PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange …

Apr 1, 2024
CVE-2024-27323
7.5 HIGH

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-23119
8.8 HIGH

Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23118
7.2 HIGH

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23117
7.2 HIGH

Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23116
7.2 HIGH

Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23115
7.2 HIGH

Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-1179
8.8 HIGH

TP-Link Omada ER605 DHCPv6 Client Options Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Apr 1, 2024
CVE-2024-0637
8.8 HIGH

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2023-51571
7.5 HIGH

Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Voltronic Power …

Apr 1, 2024
CVE-2024-30862
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

Apr 1, 2024
CVE-2024-30860
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.

Apr 1, 2024
CVE-2024-30859
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.

Apr 1, 2024
CVE-2024-25574
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_usListParameters.

Apr 1, 2024
CVE-2024-21472
8.4 HIGH

Memory corruption in Kernel while handling GPU operations.

Apr 1, 2024
CVE-2024-21470
8.4 HIGH

Memory corruption while allocating memory for graphics.

Apr 1, 2024
CVE-2024-21468
8.4 HIGH

Memory corruption when there is failed unmap operation in GPU.

Apr 1, 2024
CVE-2024-21463
7.3 HIGH

Memory corruption while processing Codec2 during v13k decoder pitch synthesis.

Apr 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.