CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44095
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44094
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no …

Sep 13, 2024
CVE-2024-44093
7.8 HIGH

In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44092
7.8 HIGH

There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege …

Sep 13, 2024
CVE-2024-29779
7.8 HIGH

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution …

Sep 13, 2024
CVE-2024-6137
7.6 HIGH

BT: Classic: SDP OOB access in get_att_search_list

Sep 13, 2024
CVE-2024-6135
7.6 HIGH

BT:Classic: Multiple missing buf length checks

Sep 13, 2024
CVE-2024-5754
8.2 HIGH

BT: Encryption procedure host vulnerability

Sep 13, 2024
CVE-2024-8281
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially …

Sep 13, 2024
CVE-2024-8280
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause …

Sep 13, 2024
CVE-2024-8279
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024
CVE-2024-8278
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024
CVE-2024-39924
8.8 HIGH

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for …

Sep 13, 2024
CVE-2024-6862
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up …

Sep 13, 2024
CVE-2024-45368
8.8 HIGH

The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E …

Sep 13, 2024
CVE-2024-43099
8.8 HIGH

The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a …

Sep 13, 2024
CVE-2024-6587
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST …

Sep 13, 2024
CVE-2024-42025
7.8 HIGH

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with …

Sep 13, 2024
CVE-2024-8269
7.3 HIGH

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions …

Sep 13, 2024
CVE-2024-7423
8.8 HIGH

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or …

Sep 13, 2024
CVE-2024-46713
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the …

Sep 13, 2024
CVE-2022-2446
7.2 HIGH

The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This …

Sep 13, 2024
CVE-2024-46047
7.5 HIGH

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.

Sep 13, 2024
CVE-2024-45113
7.5 HIGH

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability …

Sep 13, 2024
CVE-2024-45109
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-45108
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-43760
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-43756
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-45112
7.8 HIGH

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the …

Sep 13, 2024
CVE-2024-43758
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-41869
7.8 HIGH

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Sep 13, 2024
CVE-2024-41859
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-41857
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Sep 13, 2024
CVE-2024-39384
7.8 HIGH

Premiere Pro versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-39381
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-39380
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-34121
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-39377
7.8 HIGH

Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-7129
7.2 HIGH

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited …

Sep 13, 2024
CVE-2024-46699
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Disable preemption while updating GPU stats We forgot to disable preemption around the write_seqcount_begin/end() …

Sep 13, 2024
CVE-2024-46696
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded …

Sep 13, 2024
CVE-2024-46687
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk() [BUG] There is an internal report …

Sep 13, 2024
CVE-2024-46683
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: prevent UAF around preempt fence The fence lock is part of the queue, therefore …

Sep 13, 2024
CVE-2024-46674
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: st: fix probed platform device ref count on probe error path The probe …

Sep 13, 2024
CVE-2024-46673
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: aacraid: Fix double-free on probe failure aac_probe_one() calls hardware-specific init functions through the aac_driver_ident::init …

Sep 13, 2024
CVE-2024-38816
7.5 HIGH

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests …

Sep 13, 2024
CVE-2024-8751
7.5 HIGH

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. …

Sep 12, 2024
CVE-2024-8533
8.8 HIGH

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials …

Sep 12, 2024
CVE-2024-6077
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device …

Sep 12, 2024
CVE-2024-44460
7.5 HIGH

An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.