CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-34357
6.5 MEDIUM

IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. …

Feb 26, 2024
CVE-2021-46905
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hso: fix NULL-deref on disconnect regression Commit 8a12f8836145 ("net: hso: fix null-ptr-deref during tty …

Feb 26, 2024
CVE-2021-46904
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same …

Feb 26, 2024
CVE-2024-21501
5.3 MEDIUM

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration …

Feb 24, 2024
CVE-2024-1810
6.1 MEDIUM

The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode_attributes' parameter in all versions up to, and …

Feb 24, 2024
CVE-2024-22395
6.3 MEDIUM

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker …

Feb 24, 2024
CVE-2024-26188
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 23, 2024
CVE-2024-21423
4.8 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Feb 23, 2024
CVE-2021-33146
5.3 MEDIUM

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure …

Feb 23, 2024
CVE-2021-33142
6.0 MEDIUM

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable denial of …

Feb 23, 2024
CVE-2023-51394
5.3 MEDIUM

High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

Feb 23, 2024
CVE-2023-51393
5.3 MEDIUM

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as …

Feb 23, 2024
CVE-2024-27319
4.4 MEDIUM

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one …

Feb 23, 2024
CVE-2024-1825
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in CodeAstro House Rental Management System 1.0. This affects an unknown part of the component User …

Feb 23, 2024
CVE-2023-51392
6.2 MEDIUM

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel …

Feb 23, 2024
CVE-2024-1823
5.3 MEDIUM

A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php …

Feb 23, 2024
CVE-2024-1821
5.5 MEDIUM

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Feb 23, 2024
CVE-2024-26596
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events After the blamed commit, …

Feb 23, 2024
CVE-2024-26595
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path When calling mlxsw_sp_acl_tcam_region_destroy() from an error …

Feb 23, 2024
CVE-2024-25629
4.4 MEDIUM

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and …

Feb 23, 2024
CVE-2024-22776
4.7 MEDIUM

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

Feb 23, 2024
CVE-2024-1819
4.7 MEDIUM

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add …

Feb 23, 2024
CVE-2024-1818
4.7 MEDIUM

A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Feb 23, 2024
CVE-2023-52463
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efivarfs: force RO when remounting if SetVariable is not supported If SetVariable at runtime is …

Feb 23, 2024
CVE-2023-52462
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: fix check for attempt to corrupt spilled pointer When register is spilled onto a …

Feb 23, 2024
CVE-2023-52461
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix bounds limiting when given a malformed entity If we're given a malformed entity …

Feb 23, 2024
CVE-2023-52460
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference at hibernate During hibernate sequence the source context might not …

Feb 23, 2024
CVE-2023-52459
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is already …

Feb 23, 2024
CVE-2023-52458
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: add check that partition length needs to be aligned with block size Before calling …

Feb 23, 2024
CVE-2023-52456
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: imx: fix tx statemachine deadlock When using the serial port as RS485 port, the …

Feb 23, 2024
CVE-2023-52454
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the …

Feb 23, 2024
CVE-2023-52453
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume When the optional PRE_COPY support was added …

Feb 23, 2024
CVE-2024-25915
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: Free Stock Photos: from n/a through 1.2.2.

Feb 23, 2024
CVE-2023-24416
6.8 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: …

Feb 23, 2024
CVE-2024-1362
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to …

Feb 23, 2024
CVE-2024-1361
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to …

Feb 23, 2024
CVE-2024-1360
4.3 MEDIUM

The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.94. This is due to missing …

Feb 23, 2024
CVE-2024-1590
4.6 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in …

Feb 23, 2024
CVE-2023-4826
6.1 MEDIUM

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site …

Feb 23, 2024
CVE-2024-0563
4.3 MEDIUM

Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service …

Feb 23, 2024
CVE-2024-1779
5.3 MEDIUM

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 23, 2024
CVE-2024-1778
4.3 MEDIUM

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 23, 2024
CVE-2024-1777
4.3 MEDIUM

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Feb 23, 2024
CVE-2024-1781
6.3 MEDIUM

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi …

Feb 23, 2024
CVE-2024-26152
4.7 MEDIUM

### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within …

Feb 22, 2024
CVE-2024-25369
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.

Feb 22, 2024
CVE-2024-1750
5.6 MEDIUM

A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the …

Feb 22, 2024
CVE-2024-1748
5.0 MEDIUM

A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_file of the component Release Note Handler. The …

Feb 22, 2024
CVE-2024-26128
5.4 MEDIUM

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a …

Feb 22, 2024
CVE-2024-25385
6.2 MEDIUM

An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.

Feb 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.