CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53682
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regulator: axp20x: AXP717: set ramp_delay AXP717 datasheet says that regulator ramp delay is 15.625 us/step, …

Jan 11, 2025
CVE-2024-53680
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init() Under certain kernel configurations when …

Jan 11, 2025
CVE-2024-52332
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: igb: Fix potential invalid memory access in igb_init_module() The pci_register_driver() can fail and when this …

Jan 11, 2025
CVE-2024-52319
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: use aligned address in clear_gigantic_page() In current kernel, hugetlb_no_page() calls folio_zero_user() with the fault …

Jan 11, 2025
CVE-2024-51729
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: use aligned address in copy_user_gigantic_page() In current kernel, hugetlb_wp() calls copy_user_large_folio() with the fault …

Jan 11, 2025
CVE-2024-50051
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: Add cancel_work_sync before module remove If we remove the module which will call …

Jan 11, 2025
CVE-2024-49573
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix NEXT_BUDDY Adam reports that enabling NEXT_BUDDY insta triggers a WARN in pick_next_entity(). Moving …

Jan 11, 2025
CVE-2024-49571
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal msg When receiving proposal msg in server, …

Jan 11, 2025
CVE-2024-49569
5.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: unquiesce admin_q before destroy it Kernel will hang on destroy admin_q while we create …

Jan 11, 2025
CVE-2024-49568
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg When receiving proposal msg in server, the fields …

Jan 11, 2025
CVE-2024-48881
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again Commit 028ddcac477b ("bcache: Remove unnecessary NULL point check …

Jan 11, 2025
CVE-2024-48876
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: stackdepot: fix stack_depot_save_flags() in NMI context Per documentation, stack_depot_save_flags() was meant to be usable from …

Jan 11, 2025
CVE-2024-48875
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't take dev_replace rwsem on task already holding it Running fstests btrfs/011 with MKFS_OPTIONS="-O …

Jan 11, 2025
CVE-2024-48873
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: check return value of ieee80211_probereq_get() for RNR The return value of ieee80211_probereq_get() might …

Jan 11, 2025
CVE-2024-47809
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when …

Jan 11, 2025
CVE-2024-47794
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tailcall infinite loop caused by freplace There is a potential infinite loop issue …

Jan 11, 2025
CVE-2024-47408
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: check smcd_v2_ext_offset when receiving proposal msg When receiving proposal msg in server, the field …

Jan 11, 2025
CVE-2024-47143
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dma-debug: fix a possible deadlock on radix_lock radix_lock() shouldn't be held while holding dma_hash_entry[idx].lock otherwise, …

Jan 11, 2025
CVE-2024-47141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinmux: Use sequential access to access desc->pinmux data When two client of the same gpio …

Jan 11, 2025
CVE-2024-46896
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: don't access invalid sched Since 2320c9e6a768 ("drm/sched: memset() 'job' in drm_sched_job_init()") accessing job->base.sched can …

Jan 11, 2025
CVE-2024-45828
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Mask ring interrupts before ring stop request Bus cleanup path in DMA mode …

Jan 11, 2025
CVE-2024-43098
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock A deadlock may happen since …

Jan 11, 2025
CVE-2024-41935
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to shrink read extent node in batches We use rwlock to protect core …

Jan 11, 2025
CVE-2024-41932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched: fix warning in sched_setaffinity Commit 8f9ea86fdf99b added some logic to sched_setaffinity that included a …

Jan 11, 2025
CVE-2024-41149
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp callback list If the 'hctx' isn't …

Jan 11, 2025
CVE-2025-0392
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. Affected is the function datagridGraph of the …

Jan 11, 2025
CVE-2025-0391
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This issue affects the function saveOrUpdate …

Jan 11, 2025
CVE-2025-0390
5.3 MEDIUM

A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. …

Jan 11, 2025
CVE-2024-42175
2.6 LOW

HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to …

Jan 11, 2025
CVE-2024-12877
9.8 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 …

Jan 11, 2025
CVE-2024-12527
6.4 MEDIUM

The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_portal_intake_form' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-12520
6.4 MEDIUM

The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dominion_shortcodes_domain_search_6' shortcode in all versions up …

Jan 11, 2025
CVE-2024-12519
6.4 MEDIUM

The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_refresh' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-12412
6.1 MEDIUM

The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored …

Jan 11, 2025
CVE-2024-12407
6.1 MEDIUM

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, …

Jan 11, 2025
CVE-2024-12116
4.3 MEDIUM

The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via …

Jan 11, 2025
CVE-2024-11915
4.3 MEDIUM

The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due …

Jan 11, 2025
CVE-2024-11892
6.4 MEDIUM

The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_slider' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-11874
6.4 MEDIUM

The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordion' shortcode in all versions up to, and including, …

Jan 11, 2025
CVE-2024-11758
6.4 MEDIUM

The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 2.9 …

Jan 11, 2025
CVE-2024-11386
6.4 MEDIUM

The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0 …

Jan 11, 2025
CVE-2024-42174
3.7 LOW

HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of …

Jan 11, 2025
CVE-2024-42173
4.8 MEDIUM

HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force …

Jan 11, 2025
CVE-2024-42172
5.3 MEDIUM

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. …

Jan 11, 2025
CVE-2024-42171
6.4 MEDIUM

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's …

Jan 11, 2025
CVE-2024-42170
6.8 MEDIUM

HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URLs with a session token to access the victim's …

Jan 11, 2025
CVE-2024-12587
6.1 MEDIUM

The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 11, 2025
CVE-2025-23109
6.5 MEDIUM

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in …

Jan 11, 2025
CVE-2025-23108
4.3 MEDIUM

Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the …

Jan 11, 2025
CVE-2024-12304
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via button block link …

Jan 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.