CVE Database

59444+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34652
4.0 MEDIUM

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

Sep 4, 2024
CVE-2024-34651
6.2 MEDIUM

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

Sep 4, 2024
CVE-2024-34650
4.0 MEDIUM

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

Sep 4, 2024
CVE-2024-34648
5.1 MEDIUM

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

Sep 4, 2024
CVE-2024-34647
4.0 MEDIUM

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper …

Sep 4, 2024
CVE-2024-34646
6.6 MEDIUM

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

Sep 4, 2024
CVE-2024-34645
6.1 MEDIUM

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

Sep 4, 2024
CVE-2024-34644
4.4 MEDIUM

Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is …

Sep 4, 2024
CVE-2024-34643
4.4 MEDIUM

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction …

Sep 4, 2024
CVE-2024-34642
4.6 MEDIUM

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

Sep 4, 2024
CVE-2024-34641
5.1 MEDIUM

Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

Sep 4, 2024
CVE-2024-34639
4.6 MEDIUM

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

Sep 4, 2024
CVE-2024-34638
6.7 MEDIUM

Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

Sep 4, 2024
CVE-2024-34637
6.2 MEDIUM

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 …

Sep 4, 2024
CVE-2024-8298
6.2 MEDIUM

Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45449
5.1 MEDIUM

Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45448
4.1 MEDIUM

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45447
4.4 MEDIUM

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45446
5.5 MEDIUM

Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45445
4.0 MEDIUM

Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45444
5.5 MEDIUM

Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45443
6.1 MEDIUM

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Sep 4, 2024
CVE-2024-45450
4.0 MEDIUM

Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-45442
5.1 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-45441
6.2 MEDIUM

Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

Sep 4, 2024
CVE-2024-42039
4.3 MEDIUM

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 4, 2024
CVE-2024-41927
4.6 MEDIUM

Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials …

Sep 4, 2024
CVE-2024-45619
4.3 MEDIUM

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-8399
4.7 MEDIUM

Websites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.

Sep 3, 2024
CVE-2024-4629
6.5 MEDIUM

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple …

Sep 3, 2024
CVE-2024-45678
4.2 MEDIUM

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires …

Sep 3, 2024
CVE-2024-45389
6.4 MEDIUM

Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This …

Sep 3, 2024
CVE-2024-45180
5.4 MEDIUM

SquaredUp DS for SCOM 6.2.1.11104 allows XSS.

Sep 3, 2024
CVE-2024-41434
4.3 MEDIUM

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via …

Sep 3, 2024
CVE-2024-43803
4.9 MEDIUM

The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and …

Sep 3, 2024
CVE-2024-42904
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name …

Sep 3, 2024
CVE-2024-42903
6.5 MEDIUM

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link …

Sep 3, 2024
CVE-2024-42901
4.8 MEDIUM

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Sep 3, 2024
CVE-2024-43412
4.6 MEDIUM

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo …

Sep 3, 2024
CVE-2024-34463
5.1 MEDIUM

BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)

Sep 3, 2024
CVE-2024-8388
5.3 MEDIUM

Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after …

Sep 3, 2024
CVE-2024-8386
6.1 MEDIUM

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to …

Sep 3, 2024
CVE-2024-44920
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Sep 3, 2024
CVE-2024-37136
6.8 MEDIUM

Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could …

Sep 3, 2024
CVE-2024-42061
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware …

Sep 3, 2024
CVE-2024-6343
4.9 MEDIUM

A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 …

Sep 3, 2024
CVE-2024-8380
6.3 MEDIUM

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing …

Sep 3, 2024
CVE-2024-45621
5.4 MEDIUM

The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser …

Sep 2, 2024
CVE-2024-6920
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-45313
5.4 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the …

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.