CVE Database

59444+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6494
6.1 MEDIUM

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site …

Aug 7, 2024
CVE-2024-3973
4.8 MEDIUM

The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Aug 7, 2024
CVE-2024-37403
5.5 MEDIUM

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path …

Aug 7, 2024
CVE-2024-34788
6.5 MEDIUM

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

Aug 7, 2024
CVE-2024-34636
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34635
4.0 MEDIUM

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34634
4.0 MEDIUM

Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34633
4.0 MEDIUM

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34632
4.0 MEDIUM

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34631
5.5 MEDIUM

Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34630
5.5 MEDIUM

Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34629
5.5 MEDIUM

Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34628
5.5 MEDIUM

Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34627
5.5 MEDIUM

Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34626
5.5 MEDIUM

Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34625
5.5 MEDIUM

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34624
5.5 MEDIUM

Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34621
5.5 MEDIUM

Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34618
4.0 MEDIUM

Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

Aug 7, 2024
CVE-2024-34617
4.0 MEDIUM

Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

Aug 7, 2024
CVE-2024-34616
5.1 MEDIUM

Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

Aug 7, 2024
CVE-2024-34615
5.1 MEDIUM

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

Aug 7, 2024
CVE-2024-34613
4.0 MEDIUM

Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Aug 7, 2024
CVE-2024-34611
5.1 MEDIUM

Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34610
5.1 MEDIUM

Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

Aug 7, 2024
CVE-2024-34609
6.2 MEDIUM

Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34608
6.2 MEDIUM

Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34607
6.2 MEDIUM

Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34606
6.2 MEDIUM

Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34605
6.2 MEDIUM

Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-34604
6.2 MEDIUM

Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

Aug 7, 2024
CVE-2024-42218
4.7 MEDIUM

1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

Aug 6, 2024
CVE-2024-42400
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability …

Aug 6, 2024
CVE-2024-42399
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability …

Aug 6, 2024
CVE-2024-42398
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability …

Aug 6, 2024
CVE-2024-42397
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the …

Aug 6, 2024
CVE-2024-42396
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the …

Aug 6, 2024
CVE-2024-41677
6.3 MEDIUM

Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly …

Aug 6, 2024
CVE-2024-42358
6.2 MEDIUM

PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the TTF parser. Maliciously …

Aug 6, 2024
CVE-2024-39229
5.3 MEDIUM

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications …

Aug 6, 2024
CVE-2024-7564
6.5 MEDIUM

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps …

Aug 6, 2024
CVE-2024-7005
4.3 MEDIUM

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in …

Aug 6, 2024
CVE-2024-7004
4.3 MEDIUM

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in …

Aug 6, 2024
CVE-2024-7003
4.3 MEDIUM

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 6, 2024
CVE-2024-7001
4.3 MEDIUM

Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 6, 2024
CVE-2024-6999
4.3 MEDIUM

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 6, 2024
CVE-2024-6995
4.7 MEDIUM

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 6, 2024
CVE-2024-43113
6.1 MEDIUM

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-43112
6.1 MEDIUM

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-43111
6.1 MEDIUM

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.