CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6473
7.8 HIGH

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Sep 3, 2024
CVE-2024-45588
8.1 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. …

Sep 3, 2024
CVE-2024-8374
7.8 HIGH

UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of …

Sep 3, 2024
CVE-2024-45587
8.8 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. …

Sep 3, 2024
CVE-2024-45586
8.8 HIGH

This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). …

Sep 3, 2024
CVE-2024-3655
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 3, 2024
CVE-2024-38811
8.8 HIGH

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges …

Sep 3, 2024
CVE-2024-7203
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 …

Sep 3, 2024
CVE-2024-5412
7.5 HIGH

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service …

Sep 3, 2024
CVE-2024-42060
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42059
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG …

Sep 3, 2024
CVE-2024-42058
7.5 HIGH

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42057
8.1 HIGH

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from …

Sep 3, 2024
CVE-2024-1621
7.5 HIGH

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the …

Sep 2, 2024
CVE-2024-6921
7.5 HIGH

Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-45388
7.5 HIGH

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new …

Sep 2, 2024
CVE-2024-45311
7.5 HIGH

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, …

Sep 2, 2024
CVE-2024-42471
7.3 HIGH

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when …

Sep 2, 2024
CVE-2024-28100
8.9 HIGH

eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a …

Sep 2, 2024
CVE-2024-8004
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Sep 2, 2024
CVE-2024-7939
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-7938
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Sep 2, 2024
CVE-2024-7932
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-5148
7.5 HIGH

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a …

Sep 2, 2024
CVE-2024-38402
7.8 HIGH

Memory corruption while processing IOCTL call for getting group info.

Sep 2, 2024
CVE-2024-38401
7.8 HIGH

Memory corruption while processing concurrent IOCTL calls.

Sep 2, 2024
CVE-2024-33060
8.4 HIGH

Memory corruption when two threads try to map and unmap a single node simultaneously.

Sep 2, 2024
CVE-2024-33057
7.5 HIGH

Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.

Sep 2, 2024
CVE-2024-33054
7.8 HIGH

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

Sep 2, 2024
CVE-2024-33052
7.8 HIGH

Memory corruption when user provides data for FM HCI command control operations.

Sep 2, 2024
CVE-2024-33051
7.5 HIGH

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

Sep 2, 2024
CVE-2024-33050
7.5 HIGH

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

Sep 2, 2024
CVE-2024-33048
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

Sep 2, 2024
CVE-2024-33047
8.4 HIGH

Memory corruption when the captureRead QDCM command is invoked from user-space.

Sep 2, 2024
CVE-2024-33045
8.4 HIGH

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Sep 2, 2024
CVE-2024-33042
7.8 HIGH

Memory corruption when Alternative Frequency offset value is set to 255.

Sep 2, 2024
CVE-2024-33038
7.8 HIGH

Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

Sep 2, 2024
CVE-2024-33035
8.4 HIGH

Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

Sep 2, 2024
CVE-2024-23365
8.4 HIGH

Memory corruption while releasing shared resources in MinkSocket listener thread.

Sep 2, 2024
CVE-2024-23364
7.5 HIGH

Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air …

Sep 2, 2024
CVE-2024-23362
7.1 HIGH

Cryptographic issue while parsing RSA keys in COBR format.

Sep 2, 2024
CVE-2024-23359
8.2 HIGH

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

Sep 2, 2024
CVE-2024-23358
7.5 HIGH

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

Sep 2, 2024
CVE-2024-7871
8.8 HIGH

SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43776
8.8 HIGH

SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-43775
8.8 HIGH

SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via …

Sep 2, 2024
CVE-2024-43774
8.8 HIGH

SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands …

Sep 2, 2024
CVE-2024-41160
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-41157
8.8 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after …

Sep 2, 2024
CVE-2024-39816
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.