CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34631
5.5 MEDIUM

Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34630
5.5 MEDIUM

Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34629
5.5 MEDIUM

Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34628
5.5 MEDIUM

Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34627
5.5 MEDIUM

Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34626
5.5 MEDIUM

Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34625
5.5 MEDIUM

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34624
5.5 MEDIUM

Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34621
5.5 MEDIUM

Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34618
4.0 MEDIUM

Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

Aug 7, 2024
CVE-2024-34617
4.0 MEDIUM

Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

Aug 7, 2024
CVE-2024-34616
5.1 MEDIUM

Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

Aug 7, 2024
CVE-2024-34615
5.1 MEDIUM

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

Aug 7, 2024
CVE-2024-34613
4.0 MEDIUM

Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Aug 7, 2024
CVE-2024-34611
5.1 MEDIUM

Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34610
5.1 MEDIUM

Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

Aug 7, 2024
CVE-2024-34609
6.2 MEDIUM

Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34608
6.2 MEDIUM

Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34607
6.2 MEDIUM

Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34606
6.2 MEDIUM

Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34605
6.2 MEDIUM

Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34604
6.2 MEDIUM

Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-42218
4.7 MEDIUM

1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

Aug 6, 2024
CVE-2024-42400
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability …

Aug 6, 2024
CVE-2024-42399
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability …

Aug 6, 2024
CVE-2024-42398
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability …

Aug 6, 2024
CVE-2024-42397
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the …

Aug 6, 2024
CVE-2024-42396
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the …

Aug 6, 2024
CVE-2024-41677
6.3 MEDIUM

Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly …

Aug 6, 2024
CVE-2024-42358
6.2 MEDIUM

PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the TTF parser. Maliciously …

Aug 6, 2024
CVE-2024-39229
5.3 MEDIUM

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications …

Aug 6, 2024
CVE-2024-7564
6.5 MEDIUM

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps …

Aug 6, 2024
CVE-2024-7005
4.3 MEDIUM

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in …

Aug 6, 2024
CVE-2024-7004
4.3 MEDIUM

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in …

Aug 6, 2024
CVE-2024-7003
4.3 MEDIUM

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 6, 2024
CVE-2024-7001
4.3 MEDIUM

Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 6, 2024
CVE-2024-6999
4.3 MEDIUM

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 6, 2024
CVE-2024-6995
4.7 MEDIUM

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 6, 2024
CVE-2024-43113
6.1 MEDIUM

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-43112
6.1 MEDIUM

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-43111
6.1 MEDIUM

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-41333
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser …

Aug 6, 2024
CVE-2024-39751
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. …

Aug 6, 2024
CVE-2024-23460
6.4 MEDIUM

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler …

Aug 6, 2024
CVE-2023-28806
5.7 MEDIUM

An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows …

Aug 6, 2024
CVE-2024-7552
6.3 MEDIUM

A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the …

Aug 6, 2024
CVE-2024-36424
5.5 MEDIUM

K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.

Aug 6, 2024
CVE-2024-41911
5.4 MEDIUM

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a …

Aug 6, 2024
CVE-2024-41910
6.1 MEDIUM

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version …

Aug 6, 2024
CVE-2024-40101
6.1 MEDIUM

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML …

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.