CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50160
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs8409: Fix possible NULL dereference If snd_hda_gen_add_kctl fails to allocate memory and returns NULL, …

Nov 7, 2024
CVE-2024-50159
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup() Clang static checker(scan-build) throws below warning: | …

Nov 7, 2024
CVE-2024-50158
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix out of bound check Driver exports pacing stats only on GenP5 and P7 …

Nov 7, 2024
CVE-2024-50157
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop Driver waits indefinitely for the fifo …

Nov 7, 2024
CVE-2024-50156
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() If the allocation in msm_disp_state_dump_regs() failed then `block->state` can …

Nov 7, 2024
CVE-2024-50155
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netdevsim: use cond_resched() in nsim_dev_trap_report_work() I am still seeing many syzbot reports hinting that syzbot …

Nov 7, 2024
CVE-2024-50154
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(). """ …

Nov 7, 2024
CVE-2024-50153
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix null-ptr-deref in target_alloc_device() There is a null-ptr-deref issue reported by KASAN: …

Nov 7, 2024
CVE-2024-50152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_ea() Clang static checker(scan-build) warning: fs/smb/client/smb2ops.c:1304:2: Attempt to …

Nov 7, 2024
CVE-2024-50151
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL request When using encryption, either enforced by the …

Nov 7, 2024
CVE-2024-50150
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent The altmode device release refers to its …

Nov 7, 2024
CVE-2024-50149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't free job in TDR Freeing job in TDR is not safe as TDR …

Nov 7, 2024
CVE-2024-50148
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: fix wild-memory-access in proto_unregister There's issue as follows: KASAN: maybe wild-memory-access in range …

Nov 7, 2024
CVE-2024-50147
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix command bitmask initialization Command bitmask have a dedicated bit for MANAGE_PAGES command, this …

Nov 7, 2024
CVE-2024-50146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Don't call cleanup on profile rollback failure When profile rollback fails in mlx5e_netdev_change_profile, the …

Nov 7, 2024
CVE-2024-50145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx() build_skb() returns NULL in case of a …

Nov 7, 2024
CVE-2024-50144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: fix unbalanced rpm put() with fence_fini() Currently we can call fence_fini() twice if something …

Nov 7, 2024
CVE-2024-50143
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to …

Nov 7, 2024
CVE-2024-50142
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: validate new SA's prefixlen using SA family when sel.family is unset This expands the …

Nov 7, 2024
CVE-2024-50141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and context PRMT needs to find the …

Nov 7, 2024
CVE-2024-50140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/core: Disable page allocation in task_tick_mm_cid() With KASAN and PREEMPT_RT enabled, calling task_work_add() in task_tick_mm_cid() …

Nov 7, 2024
CVE-2024-50139
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix shift-out-of-bounds bug Fix a shift-out-of-bounds bug reported by UBSAN when running VM …

Nov 7, 2024
CVE-2024-10203
7.0 HIGH

Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

Nov 7, 2024
CVE-2023-1973
7.5 HIGH

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the …

Nov 7, 2024
CVE-2023-1932
6.1 MEDIUM

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. …

Nov 7, 2024
CVE-2024-30142
3.8 LOW

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by …

Nov 7, 2024
CVE-2024-30141
4.7 MEDIUM

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about …

Nov 7, 2024
CVE-2024-30140
5.4 MEDIUM

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can …

Nov 7, 2024
CVE-2024-38286
8.6 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from …

Nov 7, 2024
CVE-2024-10027
4.8 MEDIUM

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such …

Nov 7, 2024
CVE-2024-10947
4.7 MEDIUM

A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This vulnerability affects …

Nov 7, 2024
CVE-2024-10946
4.7 MEDIUM

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects …

Nov 7, 2024
CVE-2024-51990

jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the …

Nov 7, 2024
CVE-2024-51409
6.5 MEDIUM

Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format …

Nov 6, 2024
CVE-2024-48325
8.1 HIGH

Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, …

Nov 6, 2024
CVE-2024-10928
3.5 LOW

A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 6, 2024
CVE-2024-10927
3.5 LOW

A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of …

Nov 6, 2024
CVE-2024-51736
0.0 NONE

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located …

Nov 6, 2024
CVE-2024-50345
3.1 LOW

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI …

Nov 6, 2024
CVE-2024-50343
3.1 LOW

symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a …

Nov 6, 2024
CVE-2024-50342
3.1 LOW

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some …

Nov 6, 2024
CVE-2024-50341
3.1 LOW

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom …

Nov 6, 2024
CVE-2024-50340
7.3 HIGH

symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to …

Nov 6, 2024
CVE-2024-10941
6.5 MEDIUM

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

Nov 6, 2024
CVE-2024-10926
3.5 LOW

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /toggle_fold_panel.php of …

Nov 6, 2024
CVE-2024-51988
6.5 MEDIUM

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission …

Nov 6, 2024
CVE-2024-51757

happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the …

Nov 6, 2024
CVE-2024-51755
2.2 LOW

Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the …

Nov 6, 2024
CVE-2024-51754
2.2 LOW

Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not …

Nov 6, 2024
CVE-2024-51751
6.5 MEDIUM

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as …

Nov 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.