CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34642
4.6 MEDIUM

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

Sep 4, 2024
CVE-2024-34641
5.1 MEDIUM

Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

Sep 4, 2024
CVE-2024-34639
4.6 MEDIUM

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

Sep 4, 2024
CVE-2024-34638
6.7 MEDIUM

Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

Sep 4, 2024
CVE-2024-34637
6.2 MEDIUM

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 …

Sep 4, 2024
CVE-2024-8298
6.2 MEDIUM

Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45449
5.1 MEDIUM

Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45448
4.1 MEDIUM

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45447
4.4 MEDIUM

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45446
5.5 MEDIUM

Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45445
4.0 MEDIUM

Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45444
5.5 MEDIUM

Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45443
6.1 MEDIUM

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Sep 4, 2024
CVE-2024-45450
4.0 MEDIUM

Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45442
5.1 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45441
6.2 MEDIUM

Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-42039
4.3 MEDIUM

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-41927
4.6 MEDIUM

Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials …

Sep 4, 2024
CVE-2024-45619
4.3 MEDIUM

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-8399
4.7 MEDIUM

Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.

Sep 3, 2024
CVE-2024-4629
6.5 MEDIUM

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple …

Sep 3, 2024
CVE-2024-45678
4.2 MEDIUM

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires …

Sep 3, 2024
CVE-2024-45389
6.4 MEDIUM

Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This …

Sep 3, 2024
CVE-2024-45180
5.4 MEDIUM

SquaredUp DS for SCOM 6.2.1.11104 allows XSS.

Sep 3, 2024
CVE-2024-41434
4.3 MEDIUM

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via …

Sep 3, 2024
CVE-2024-43803
4.9 MEDIUM

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and …

Sep 3, 2024
CVE-2024-42904
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name …

Sep 3, 2024
CVE-2024-42903
6.5 MEDIUM

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link …

Sep 3, 2024
CVE-2024-42901
4.8 MEDIUM

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Sep 3, 2024
CVE-2024-43412
4.6 MEDIUM

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo …

Sep 3, 2024
CVE-2024-34463
5.1 MEDIUM

BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)

Sep 3, 2024
CVE-2024-8388
5.3 MEDIUM

Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after …

Sep 3, 2024
CVE-2024-8386
6.1 MEDIUM

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to …

Sep 3, 2024
CVE-2024-44920
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Sep 3, 2024
CVE-2024-37136
6.8 MEDIUM

Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could …

Sep 3, 2024
CVE-2024-42061
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware …

Sep 3, 2024
CVE-2024-6343
4.9 MEDIUM

A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 …

Sep 3, 2024
CVE-2024-8380
6.3 MEDIUM

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing …

Sep 3, 2024
CVE-2024-45621
5.4 MEDIUM

The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser …

Sep 2, 2024
CVE-2024-6920
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-45313
5.4 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the …

Sep 2, 2024
CVE-2024-45312
5.3 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a …

Sep 2, 2024
CVE-2024-45308
6.5 MEDIUM

HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with …

Sep 2, 2024
CVE-2024-45306
4.5 MEDIUM

Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that …

Sep 2, 2024
CVE-2024-44947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page …

Sep 2, 2024
CVE-2024-43801
4.6 MEDIUM

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack against …

Sep 2, 2024
CVE-2024-43797
6.3 MEDIUM

audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission …

Sep 2, 2024
CVE-2024-43792
6.3 MEDIUM

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability …

Sep 2, 2024
CVE-2020-36830
4.3 MEDIUM

A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of …

Sep 2, 2024
CVE-2024-38858
6.1 MEDIUM

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.