CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49300
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows Reflected XSS. This …

Jan 21, 2025
CVE-2024-32555
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in InspiryThemes Easy Real Estate easy-real-estate allows Privilege Escalation.This issue affects Easy Real Estate: from n/a through <= 2.2.9.

Jan 21, 2025
CVE-2025-21664
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm thin: make get_first_thin use rcu-safe list first function The documentation in rculist.h explains the …

Jan 21, 2025
CVE-2025-21663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require …

Jan 21, 2025
CVE-2025-21662
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to …

Jan 21, 2025
CVE-2025-21661
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix missing lookup table cleanups When a virtuser device is created via configfs …

Jan 21, 2025
CVE-2025-21660
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked When `ksmbd_vfs_kern_path_locked` met an error and it is …

Jan 21, 2025
CVE-2025-21659
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netdev: prevent accessing NAPI instances from another namespace The NAPI IDs were not fully exposed …

Jan 21, 2025
CVE-2025-21658
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid NULL pointer dereference if no valid extent tree [BUG] Syzbot reported a crash …

Jan 21, 2025
CVE-2025-21657
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Replace rq_lock() to raw_spin_rq_lock() in scx_ops_bypass() scx_ops_bypass() iterates all CPUs to re-enqueue all the …

Jan 21, 2025
CVE-2025-21656
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur scsi_execute_cmd() function can return …

Jan 21, 2025
CVE-2024-57946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-blk: don't keep queue frozen during system suspend Commit 4ce6e2db00de ("virtio-blk: Ensure no requests in …

Jan 21, 2025
CVE-2024-57945
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Fix the out of bound issue of vmemmap address In sparse vmemmap model, …

Jan 21, 2025
CVE-2024-57944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: Add NULL check in ads1298_init devm_kasprintf() can return a NULL pointer on …

Jan 21, 2025
CVE-2024-57943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: exfat: fix the new buffer was not zeroed before writing Before writing, if a buffer_head …

Jan 21, 2025
CVE-2024-57942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix ceph copy to cache on write-begin At the end of netfs_unlock_read_folio() in which …

Jan 21, 2025
CVE-2024-57941
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled When the caching for …

Jan 21, 2025
CVE-2024-57940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: exfat: fix the infinite loop in exfat_readdir() If the file system is corrupted so that …

Jan 21, 2025
CVE-2024-57939
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix sleeping in invalid context in die() die() can be called in exception handler, …

Jan 21, 2025
CVE-2025-0615
5.3 MEDIUM

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an attacker to modify an email to contain the ‘+’ symbol to access the …

Jan 21, 2025
CVE-2025-0614
5.3 MEDIUM

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case …

Jan 21, 2025
CVE-2024-57938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sctp: Prevent autoclose integer overflow in sctp_association_init() While by default max_autoclose equals to INT_MAX / …

Jan 21, 2025
CVE-2024-57937

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 21, 2025
CVE-2024-57936
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix max SGEs for the Work Request Gen P7 supports up to 13 SGEs …

Jan 21, 2025
CVE-2024-57935
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix accessing invalid dip_ctx during destroying QP If it fails to modify QP to …

Jan 21, 2025
CVE-2024-57934
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fgraph: Add READ_ONCE() when accessing fgraph_array[] In __ftrace_return_to_handler(), a loop iterates over the fgraph_array[] elements, …

Jan 21, 2025
CVE-2024-57933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gve: guard XSK operations on the existence of queues This patch predicates the enabling and …

Jan 21, 2025
CVE-2024-57932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gve: guard XDP xmit NDO on existence of xdp queues In GVE, dedicated XDP queues …

Jan 21, 2025
CVE-2024-57931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: selinux: ignore unknown extended permissions When evaluating extended permissions, ignore unknown permissions instead of calling …

Jan 21, 2025
CVE-2024-57930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Have process_string() also allow arrays In order to catch a common bug where a …

Jan 21, 2025
CVE-2025-0450
6.4 MEDIUM

The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and including, 27.6.1 …

Jan 21, 2025
CVE-2024-52973
6.5 MEDIUM

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summary. This can …

Jan 21, 2025
CVE-2024-43709
6.5 MEDIUM

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query …

Jan 21, 2025
CVE-2024-37284
5.5 MEDIUM

Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This …

Jan 21, 2025
CVE-2024-13444
6.1 MEDIUM

The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or …

Jan 21, 2025
CVE-2024-13230
5.3 MEDIUM

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter …

Jan 21, 2025
CVE-2024-11226
6.4 MEDIUM

The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in all versions up to, and …

Jan 21, 2025
CVE-2025-23184
5.9 MEDIUM

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances …

Jan 21, 2025
CVE-2024-6466
5.3 MEDIUM

NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.

Jan 21, 2025
CVE-2024-13404
6.1 MEDIUM

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due …

Jan 21, 2025
CVE-2024-12104
5.3 MEDIUM

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability …

Jan 21, 2025
CVE-2024-12005
6.1 MEDIUM

The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or …

Jan 21, 2025
CVE-2025-0371
6.4 MEDIUM

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient …

Jan 21, 2025
CVE-2024-10936
8.8 HIGH

The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input …

Jan 21, 2025
CVE-2025-23086
6.1 MEDIUM

On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site …

Jan 21, 2025
CVE-2024-13536
5.3 MEDIUM

The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the …

Jan 21, 2025
CVE-2024-45091
6.2 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read …

Jan 21, 2025
CVE-2025-24014
4.2 MEDIUM

Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim …

Jan 20, 2025
CVE-2024-13454
5.3 MEDIUM

Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL …

Jan 20, 2025
CVE-2025-23214

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. By …

Jan 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.