CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24702
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

Feb 28, 2024
CVE-2023-6917
6.0 MEDIUM

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While …

Feb 28, 2024
CVE-2024-1965
6.5 MEDIUM

Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need …

Feb 28, 2024
CVE-2024-1808
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up …

Feb 28, 2024
CVE-2024-26016
4.3 MEDIUM

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Feb 28, 2024
CVE-2024-24779
5.0 MEDIUM

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to …

Feb 28, 2024
CVE-2024-24773
4.9 MEDIUM

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, …

Feb 28, 2024
CVE-2024-24772
4.3 MEDIUM

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics …

Feb 28, 2024
CVE-2024-27315
4.3 MEDIUM

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an …

Feb 28, 2024
CVE-2024-1861
4.3 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1860
6.5 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1719
4.3 MEDIUM

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 …

Feb 28, 2024
CVE-2024-22459
6.8 MEDIUM

Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged …

Feb 28, 2024
CVE-2024-1954
6.3 MEDIUM

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Feb 28, 2024
CVE-2024-1791
6.4 MEDIUM

The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 …

Feb 28, 2024
CVE-2024-1566
6.5 MEDIUM

The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in all versions …

Feb 28, 2024
CVE-2024-1516
5.3 MEDIUM

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all …

Feb 28, 2024
CVE-2024-1476
5.3 MEDIUM

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 …

Feb 28, 2024
CVE-2024-1368
5.3 MEDIUM

The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_dat_page() function in all …

Feb 28, 2024
CVE-2024-1136
5.3 MEDIUM

The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in …

Feb 28, 2024
CVE-2024-0975
5.3 MEDIUM

The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. …

Feb 28, 2024
CVE-2024-0768
4.3 MEDIUM

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4.4. This …

Feb 28, 2024
CVE-2024-0767
4.3 MEDIUM

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This …

Feb 28, 2024
CVE-2024-0766
4.3 MEDIUM

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Feb 28, 2024
CVE-2024-0682
5.3 MEDIUM

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin …

Feb 28, 2024
CVE-2024-0680
5.3 MEDIUM

The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to …

Feb 28, 2024
CVE-2024-0433
4.3 MEDIUM

The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to …

Feb 28, 2024
CVE-2024-0432
4.3 MEDIUM

The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to …

Feb 28, 2024
CVE-2024-0431
4.3 MEDIUM

The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to …

Feb 28, 2024
CVE-2023-6922
4.3 MEDIUM

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via …

Feb 28, 2024
CVE-2021-47053
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of pad It appears there are several failure return …

Feb 28, 2024
CVE-2021-47052
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sa2ul - Fix memory leak of rxd There are two error return paths that …

Feb 28, 2024
CVE-2021-47051
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: Fix PM reference leak in lpspi_prepare_xfer_hardware() pm_runtime_get_sync will increment pm usage counter even …

Feb 28, 2024
CVE-2021-47050
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memory: renesas-rpc-if: fix possible NULL pointer dereference of resource The platform_get_resource_byname() can return NULL which …

Feb 28, 2024
CVE-2021-47047
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: return -ENOMEM if dma_map_single fails The spi controller supports 44-bit address space on …

Feb 28, 2024
CVE-2021-47045
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix null pointer dereference in lpfc_prep_els_iocb() It is possible to call lpfc_issue_els_plogi() passing …

Feb 28, 2024
CVE-2021-47043
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: venus: core: Fix some resource leaks in the error path of 'venus_probe()' If an …

Feb 28, 2024
CVE-2021-47042
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Free local data after use Fixes the following memory leak in dc_link_construct(): unreferenced object …

Feb 28, 2024
CVE-2021-47041
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix incorrect locking in state_change sk callback We are not changing anything in the …

Feb 28, 2024
CVE-2021-47038
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: avoid deadlock between hci_dev->lock and socket lock Commit eab2404ba798 ("Bluetooth: Add BT_PHY socket option") …

Feb 28, 2024
CVE-2021-47037
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: q6afe-clocks: fix reprobing of the driver Q6afe-clocks driver can get reprobed. For example if …

Feb 28, 2024
CVE-2021-47036
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: udp: skip L4 aggregation for UDP tunnel packets If NETIF_F_GRO_FRAGLIST or NETIF_F_GRO_UDP_FWD are enabled, and …

Feb 28, 2024
CVE-2021-47035
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Remove WO permissions on second-level paging entries When the first level page table is …

Feb 28, 2024
CVE-2021-47034
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix pte update for kernel memory on radix When adding a PTE a ptesync …

Feb 28, 2024
CVE-2021-47033
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7615: fix tx skb dma unmap The first pointer in the txp needs to …

Feb 28, 2024
CVE-2021-47032
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7915: fix tx skb dma unmap The first pointer in the txp needs to …

Feb 28, 2024
CVE-2021-47031
4.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix memory leak in mt7921_coredump_work Fix possible memory leak in mt7921_coredump_work.

Feb 28, 2024
CVE-2021-47030
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7615: fix memory leak in mt7615_coredump_work Similar to the issue fixed in mt7921_coredump_work, fix …

Feb 28, 2024
CVE-2021-47029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: connac: fix kernel warning adding monitor interface Fix the following kernel warning adding a …

Feb 28, 2024
CVE-2021-47027
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix kernel crash when the firmware fails to download Fix kernel crash when …

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.