CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix deadlock during RTC update There is a deadlock when runtime suspend …

Sep 4, 2024
CVE-2024-44950
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: fix invalid FIFO access with special register set When enabling access to the …

Sep 4, 2024
CVE-2024-44948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed variant …

Sep 4, 2024
CVE-2024-8416
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Sep 4, 2024
CVE-2024-45177
5.4 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent …

Sep 4, 2024
CVE-2024-8415
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Sep 4, 2024
CVE-2024-8414
4.3 MEDIUM

A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation …

Sep 4, 2024
CVE-2024-20503
5.5 MEDIUM

A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This …

Sep 4, 2024
CVE-2024-20497
4.3 MEDIUM

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is …

Sep 4, 2024
CVE-2024-20469
6.0 MEDIUM

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the …

Sep 4, 2024
CVE-2024-8412
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comments/views.py. The …

Sep 4, 2024
CVE-2024-45074
6.5 MEDIUM

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing …

Sep 4, 2024
CVE-2024-45052
5.3 MEDIUM

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an …

Sep 4, 2024
CVE-2024-44821
5.3 MEDIUM

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a …

Sep 4, 2024
CVE-2024-44818
5.4 MEDIUM

Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.

Sep 4, 2024
CVE-2024-8410
4.3 MEDIUM

A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of …

Sep 4, 2024
CVE-2024-8409
4.3 MEDIUM

A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation …

Sep 4, 2024
CVE-2024-7077
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects Semtek …

Sep 4, 2024
CVE-2024-44820
6.1 MEDIUM

A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, …

Sep 4, 2024
CVE-2024-44819
6.1 MEDIUM

Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via a crafted script to the pagename parameter …

Sep 4, 2024
CVE-2024-8408
6.3 MEDIUM

A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file …

Sep 4, 2024
CVE-2024-44383
6.8 MEDIUM

WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.

Sep 4, 2024
CVE-2024-8413
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://github.com/Bioshox/Raspcontrol and forks such as https://github.com/harmon25/raspcontrol . An attacker could exploit …

Sep 4, 2024
CVE-2024-7870
6.5 MEDIUM

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all …

Sep 4, 2024
CVE-2024-8318
6.4 MEDIUM

The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 …

Sep 4, 2024
CVE-2024-8123
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Sep 4, 2024
CVE-2024-8121
5.4 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check …

Sep 4, 2024
CVE-2024-8119
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up …

Sep 4, 2024
CVE-2024-8117
6.1 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up …

Sep 4, 2024
CVE-2024-8106
6.5 MEDIUM

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 …

Sep 4, 2024
CVE-2024-8325
6.4 MEDIUM

The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding …

Sep 4, 2024
CVE-2024-7786
5.3 MEDIUM

The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.

Sep 4, 2024
CVE-2024-6889
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6888
4.8 MEDIUM

The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high …

Sep 4, 2024
CVE-2024-6722
4.8 MEDIUM

The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow …

Sep 4, 2024
CVE-2024-6020
6.1 MEDIUM

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, …

Sep 4, 2024
CVE-2024-34661
4.3 MEDIUM

Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering …

Sep 4, 2024
CVE-2024-34658
4.0 MEDIUM

Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

Sep 4, 2024
CVE-2024-34655
6.2 MEDIUM

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

Sep 4, 2024
CVE-2024-34654
6.2 MEDIUM

Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

Sep 4, 2024
CVE-2024-34653
4.6 MEDIUM

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

Sep 4, 2024
CVE-2024-34652
4.0 MEDIUM

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

Sep 4, 2024
CVE-2024-34651
6.2 MEDIUM

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

Sep 4, 2024
CVE-2024-34650
4.0 MEDIUM

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

Sep 4, 2024
CVE-2024-34648
5.1 MEDIUM

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

Sep 4, 2024
CVE-2024-34647
4.0 MEDIUM

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper …

Sep 4, 2024
CVE-2024-34646
6.6 MEDIUM

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

Sep 4, 2024
CVE-2024-34645
6.1 MEDIUM

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

Sep 4, 2024
CVE-2024-34644
4.4 MEDIUM

Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is …

Sep 4, 2024
CVE-2024-34643
4.4 MEDIUM

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.