CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-57915

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 19, 2025
CVE-2024-57914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci: fix NULL pointer issue on shared irq case The tcpci_irq() may meet …

Jan 19, 2025
CVE-2024-57913
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Remove WARN_ON in functionfs_bind This commit addresses an issue related to below …

Jan 19, 2025
CVE-2024-57912
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: pressure: zpa2326: fix information leak in triggered buffer The 'sample' local struct is used …

Jan 19, 2025
CVE-2024-57911
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer The 'data' array is allocated via …

Jan 19, 2025
CVE-2024-57910
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: light: vcnl4035: fix information leak in triggered buffer The 'buffer' local array is used …

Jan 19, 2025
CVE-2024-57909
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: light: bh1745: fix information leak in triggered buffer The 'scan' local struct is used …

Jan 19, 2025
CVE-2024-57908
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered buffer The 'buffer' local array is used …

Jan 19, 2025
CVE-2024-57907
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in triggered buffer The 'data' local struct is used …

Jan 19, 2025
CVE-2024-57906
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads8688: fix information leak in triggered buffer The 'buffer' local array is used …

Jan 19, 2025
CVE-2024-57905
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix information leak in triggered buffer The 'scan' local struct is used …

Jan 19, 2025
CVE-2024-57904
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocated iio_dev Current implementation of at91_ts_register() calls input_free_deivce() on …

Jan 19, 2025
CVE-2025-21654
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ovl: support encoding fid from inode with no alias Dmitry Safonov reported that a WARN_ON() …

Jan 19, 2025
CVE-2025-21653
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute syzbot found that TCA_FLOW_RSHIFT attribute was not validated. Right shitfing …

Jan 19, 2025
CVE-2025-21652
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix use-after-free in ipvlan_get_iflink(). syzbot presented an use-after-free report [0] regarding ipvlan and linkwatch. …

Jan 19, 2025
CVE-2025-21651
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: don't auto enable misc vector Currently, there is a time window between misc …

Jan 19, 2025
CVE-2025-21650
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue The TQP BAR space …

Jan 19, 2025
CVE-2025-21649
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when 1588 is sent on HIP08 devices Currently, HIP08 devices …

Jan 19, 2025
CVE-2025-21648
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: clamp maximum hashtable size to INT_MAX Use INT_MAX as maximum size for the …

Jan 19, 2025
CVE-2025-21647
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed …

Jan 19, 2025
CVE-2025-21646
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: afs: Fix the maximum cell name length The kafs filesystem limits the maximum length of …

Jan 19, 2025
CVE-2025-21645
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it Wakeup for IRQ1 should be …

Jan 19, 2025
CVE-2025-21644
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix tlb invalidation when wedging If GuC fails to load, the driver wedges, but …

Jan 19, 2025
CVE-2025-21643
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix kernel async DIO Netfslib needs to be able to handle kernel-initiated asynchronous DIO …

Jan 19, 2025
CVE-2025-21642
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: sysctl: sched: avoid using current->nsproxy Using the 'net' structure via 'current' is not recommended …

Jan 19, 2025
CVE-2025-21641
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: sysctl: blackhole timeout: avoid using current->nsproxy As mentioned in the previous commit, using the …

Jan 19, 2025
CVE-2025-21640
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21639
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: rto_min/max: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21638
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: auth_enable: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21637
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: udp_port: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21636
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21635
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy As mentioned in a previous commit of this series, …

Jan 19, 2025
CVE-2025-21634
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: remove kernfs active break A warning was found: WARNING: CPU: 10 PID: 3486953 at …

Jan 19, 2025
CVE-2025-21633

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 19, 2025
CVE-2025-21632
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure shadow stack is active before "getting" registers The x86 shadow stack support has …

Jan 19, 2025
CVE-2025-21631
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix waker_bfqq UAF after bfq_split_bfqq() Our syzkaller report a following UAF for v6.6: …

Jan 19, 2025
CVE-2025-0567
4.5 MEDIUM

A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unknown code in the library profapi.dll of the …

Jan 19, 2025
CVE-2025-0566
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNetName of the file /goform/SetDevNetName. The manipulation of the …

Jan 19, 2025
CVE-2025-0565
7.3 HIGH

A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. …

Jan 19, 2025
CVE-2024-8722
5.5 MEDIUM

The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all …

Jan 19, 2025
CVE-2025-0564
7.3 HIGH

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 19, 2025
CVE-2024-45654
4.3 MEDIUM

IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.

Jan 19, 2025
CVE-2024-45653
4.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authenticated users in responses that could be used …

Jan 19, 2025
CVE-2024-45652
6.5 MEDIUM

IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Jan 19, 2025
CVE-2025-0563
6.3 MEDIUM

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been classified as critical. Affected is an unknown function of the file /dash/update.php. The manipulation …

Jan 19, 2025
CVE-2025-0562
6.3 MEDIUM

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/health_status_entry.php. The …

Jan 19, 2025
CVE-2025-0561
6.3 MEDIUM

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-pig.php. The …

Jan 19, 2025
CVE-2024-45662
7.5 HIGH

IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due …

Jan 18, 2025
CVE-2024-49824
6.5 MEDIUM

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through …

Jan 18, 2025
CVE-2024-49354
5.3 MEDIUM

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

Jan 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.