CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4594
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/sys_safe.php. The manipulation leads to …

May 7, 2024
CVE-2024-33122
6.3 MEDIUM

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.

May 7, 2024
CVE-2024-32867
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of …

May 7, 2024
CVE-2024-32664
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets …

May 7, 2024
CVE-2024-32369
4.3 MEDIUM

SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the …

May 7, 2024
CVE-2024-4593
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation …

May 7, 2024
CVE-2024-4592
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request …

May 7, 2024
CVE-2024-4591
4.3 MEDIUM

A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site …

May 7, 2024
CVE-2024-4590
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. …

May 7, 2024
CVE-2024-33783
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33780
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-28148
4.3 MEDIUM

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects …

May 7, 2024
CVE-2024-4589
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. …

May 7, 2024
CVE-2024-4588
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads …

May 7, 2024
CVE-2024-4587
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7 and classified as problematic. This issue affects some unknown processing of the file /src/dede/tpl.php. The manipulation leads to …

May 7, 2024
CVE-2024-4586
4.3 MEDIUM

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/shops_delivery.php. The manipulation leads to …

May 7, 2024
CVE-2024-4536
6.8 MEDIUM

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from …

May 7, 2024
CVE-2023-7240
5.8 MEDIUM

An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open …

May 7, 2024
CVE-2023-31234
6.3 MEDIUM

Missing Authorization vulnerability in Tilda Publishing.This issue affects Tilda Publishing: from n/a through 0.3.23.

May 7, 2024
CVE-2024-4601
6.7 MEDIUM

An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perform a brute force attack …

May 7, 2024
CVE-2024-4585
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to …

May 7, 2024
CVE-2024-4584
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Faraday GM8181 and GM828x up to 20240429. Affected by this issue is some unknown …

May 7, 2024
CVE-2024-4583
5.3 MEDIUM

A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the …

May 7, 2024
CVE-2023-6810
4.3 MEDIUM

The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function …

May 7, 2024
CVE-2024-3759
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

May 7, 2024
CVE-2024-3758
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

May 7, 2024
CVE-2024-27217
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

May 7, 2024
CVE-2024-23808
5.2 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL …

May 7, 2024
CVE-2024-20872
6.2 MEDIUM

Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

May 7, 2024
CVE-2024-20871
4.9 MEDIUM

Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

May 7, 2024
CVE-2024-20870
5.1 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege …

May 7, 2024
CVE-2024-20869
5.5 MEDIUM

Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.

May 7, 2024
CVE-2024-20868
4.4 MEDIUM

Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.

May 7, 2024
CVE-2024-20867
5.5 MEDIUM

Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.

May 7, 2024
CVE-2024-20866
5.7 MEDIUM

Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

May 7, 2024
CVE-2024-20865
6.6 MEDIUM

Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.

May 7, 2024
CVE-2024-20864
5.5 MEDIUM

Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.

May 7, 2024
CVE-2024-20863
6.7 MEDIUM

Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

May 7, 2024
CVE-2024-20862
6.0 MEDIUM

Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

May 7, 2024
CVE-2024-20861
6.0 MEDIUM

Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.

May 7, 2024
CVE-2024-20860
4.0 MEDIUM

Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.

May 7, 2024
CVE-2024-20859
5.5 MEDIUM

Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

May 7, 2024
CVE-2024-20858
4.0 MEDIUM

Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

May 7, 2024
CVE-2024-20857
4.0 MEDIUM

Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

May 7, 2024
CVE-2024-20856
4.3 MEDIUM

Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific …

May 7, 2024
CVE-2024-20821
4.4 MEDIUM

A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode, which disables security features. This attack needs additional privilege to …

May 7, 2024
CVE-2024-2913
6.5 MEDIUM

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent …

May 7, 2024
CVE-2024-34413
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Stored XSS.This issue affects SliceWP: from n/a through 1.1.10.

May 6, 2024
CVE-2024-1695
5.7 MEDIUM

A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC products, which might allow escalation of privilege. …

May 6, 2024
CVE-2023-33548
6.8 MEDIUM

Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA …

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.