CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-38360
6.1 MEDIUM

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 4, 2024
CVE-2021-47100
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix UAF when uninstall ipmi_si and ipmi_msghandler module Hi, When testing install and uninstall …

Mar 4, 2024
CVE-2021-47099
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: veth: ensure skb entering GRO are not cloned. After commit d3256efd8e8b ("veth: allow enabling NAPI …

Mar 4, 2024
CVE-2021-47096
4.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space …

Mar 4, 2024
CVE-2021-47095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi: ssif: initialize ssif_info->client early During probe ssif_info->client is dereferenced in error path. However, it …

Mar 4, 2024
CVE-2021-47093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel_pmc_core: fix memleak on registration failure In case device registration fails during module initialisation, …

Mar 4, 2024
CVE-2021-47092
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Always clear vmx->fail on emulation_required Revert a relatively recent change that set vmx->fail …

Mar 4, 2024
CVE-2021-47091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix locking in ieee80211_start_ap error path We need to hold the local->mtx to release …

Mar 4, 2024
CVE-2021-47090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() Hulk Robot reported a panic in put_page_testzero() when testing …

Mar 4, 2024
CVE-2021-47086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phonet/pep: refuse to enable an unbound pipe This ioctl() implicitly assumed that the socket was …

Mar 4, 2024
CVE-2023-5451
6.1 MEDIUM

Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of …

Mar 4, 2024
CVE-2023-38362
5.3 MEDIUM

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.

Mar 4, 2024
CVE-2022-43890
5.3 MEDIUM

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. …

Mar 4, 2024
CVE-2024-27680
6.1 MEDIUM

Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."

Mar 4, 2024
CVE-2024-27668
6.1 MEDIUM

Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'

Mar 4, 2024
CVE-2024-27684
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML …

Mar 4, 2024
CVE-2023-33090
5.5 MEDIUM

Transient DOS while processing channel information for speaker protection v2 module in ADSP.

Mar 4, 2024
CVE-2023-33078
5.1 MEDIUM

Information Disclosure while processing IOCTL request in FastRPC.

Mar 4, 2024
CVE-2024-21826
4.3 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

Mar 4, 2024
CVE-2024-21816
4.0 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

Mar 4, 2024
CVE-2023-46708
4.3 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

Mar 4, 2024
CVE-2024-20037
6.7 MEDIUM

In pq, there is a possible write-what-where condition due to an incorrect bounds check. This could lead to local escalation of privilege with System execution …

Mar 4, 2024
CVE-2024-20036
4.4 MEDIUM

In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. …

Mar 4, 2024
CVE-2024-20033
4.4 MEDIUM

In nvram, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Mar 4, 2024
CVE-2024-20032
6.7 MEDIUM

In aee, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution …

Mar 4, 2024
CVE-2024-20031
6.7 MEDIUM

In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20030
4.4 MEDIUM

In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. …

Mar 4, 2024
CVE-2024-20028
6.6 MEDIUM

In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20026
4.2 MEDIUM

In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. …

Mar 4, 2024
CVE-2024-20025
6.7 MEDIUM

In da, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20024
6.0 MEDIUM

In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20023
6.7 MEDIUM

In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20022
6.7 MEDIUM

In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20020
4.4 MEDIUM

In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System …

Mar 4, 2024
CVE-2024-20019
5.9 MEDIUM

In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional …

Mar 4, 2024
CVE-2024-2156
6.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 4, 2024
CVE-2024-2155
4.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. …

Mar 4, 2024
CVE-2024-2154
6.3 MEDIUM

A vulnerability has been found in SourceCodester Online Mobile Management Store 1.0 and classified as critical. This vulnerability affects unknown code of the file view_product.php. …

Mar 4, 2024
CVE-2024-2153
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Online Mobile Management Store 1.0. This affects an unknown part of the file /admin/orders/view_order.php. …

Mar 4, 2024
CVE-2024-2152
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Mobile Management Store 1.0. Affected by this issue is some unknown functionality …

Mar 4, 2024
CVE-2024-2151
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Online Mobile Management Store 1.0. Affected by this vulnerability is an unknown functionality of the component …

Mar 4, 2024
CVE-2019-25210
6.5 MEDIUM

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This …

Mar 3, 2024
CVE-2024-2150
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. This issue affects some unknown processing. The manipulation of …

Mar 3, 2024
CVE-2024-2149
4.7 MEDIUM

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of …

Mar 3, 2024
CVE-2024-2148
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Mobile Management Store 1.0. This affects an unknown part of the file /classes/Users.php. The …

Mar 3, 2024
CVE-2023-28512
5.9 MEDIUM

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improper …

Mar 3, 2024
CVE-2023-27291
4.5 MEDIUM

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an …

Mar 3, 2024
CVE-2022-43880
4.4 MEDIUM

IBM QRadar WinCollect Agent 10.0 through 10.1.2 could allow a privileged user to cause a denial of service. IBM X-Force ID: 240151.

Mar 3, 2024
CVE-2024-0765
6.5 MEDIUM

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip …

Mar 3, 2024
CVE-2024-22355
5.9 MEDIUM

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords …

Mar 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.