CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10479
2.4 LOW

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of …

Oct 29, 2024
CVE-2024-50088
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free in add_inode_ref() The add_inode_ref() function does not initialize the "name" …

Oct 29, 2024
CVE-2024-50087
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free on read_alloc_one_name() error The function read_alloc_one_name() does not initialize the …

Oct 29, 2024
CVE-2024-50086
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session log …

Oct 29, 2024
CVE-2024-50085
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow Syzkaller reported this splat: ================================================================== BUG: KASAN: slab-use-after-free …

Oct 29, 2024
CVE-2024-50084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() Commit a3c1e45156ad ("net: microchip: vcap: Fix …

Oct 29, 2024
CVE-2024-50083
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger …

Oct 29, 2024
CVE-2024-50082
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race We're seeing crashes from rq_qos_wake_function that look …

Oct 29, 2024
CVE-2024-50081
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-mq: setup queue ->tag_set before initializing hctx Commit 7b815817aa58 ("blk-mq: add helper for checking if …

Oct 29, 2024
CVE-2024-50080
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on …

Oct 29, 2024
CVE-2024-50079
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work When the sqpoll is exiting and …

Oct 29, 2024
CVE-2024-50078
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Call iso_exit() on module unload If iso_init() has been called, iso_exit() must be called …

Oct 29, 2024
CVE-2024-50077
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix multiple init when debugfs is disabled If bt_debugfs is not created successfully, …

Oct 29, 2024
CVE-2024-50076
6.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the …

Oct 29, 2024
CVE-2024-50075
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xhci: tegra: fix checked USB2 port number If USB virtualizatoin is enabled, USB2 ports are …

Oct 29, 2024
CVE-2024-50074
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access The recent fix for array out-of-bounds accesses replaced …

Oct 29, 2024
CVE-2024-50073
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Fix use-after-free in gsm_cleanup_mux BUG: KASAN: slab-use-after-free in gsm_cleanup_mux+0x77b/0x7b0 drivers/tty/n_gsm.c:3160 [n_gsm] Read of …

Oct 29, 2024
CVE-2024-50072
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Use code segment selector for VERW operand Robert Gill reported below #GP in 32-bit …

Oct 29, 2024
CVE-2024-50071
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func() 'new_map' is allocated using devm_* which takes …

Oct 29, 2024
CVE-2024-50070
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: stm32: check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but …

Oct 29, 2024
CVE-2024-50069
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: apple: check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but …

Oct 29, 2024
CVE-2024-50068
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/tests/sysfs-kunit.h: fix memory leak in damon_sysfs_test_add_targets() The sysfs_target->regions allocated in damon_sysfs_regions_alloc() is not freed in …

Oct 29, 2024
CVE-2024-45656
9.8 CRITICAL

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which …

Oct 29, 2024
CVE-2024-10478
2.4 LOW

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file …

Oct 29, 2024
CVE-2024-10477
2.4 LOW

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component …

Oct 29, 2024
CVE-2024-51509
4.8 MEDIUM

Tiki through 27.0 allows users who have certain permissions to insert a "Modules" (aka tiki-admin_modules.php) stored XSS payload in the Name.

Oct 28, 2024
CVE-2024-51508
4.8 MEDIUM

Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Index.

Oct 28, 2024
CVE-2024-51507
4.8 MEDIUM

Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.

Oct 28, 2024
CVE-2024-51506
4.8 MEDIUM

Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.

Oct 28, 2024
CVE-2024-44295
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may …

Oct 28, 2024
CVE-2024-44283
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a …

Oct 28, 2024
CVE-2024-44260
4.4 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious …

Oct 28, 2024
CVE-2024-44257
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An …

Oct 28, 2024
CVE-2024-44256
8.6 HIGH

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may …

Oct 28, 2024
CVE-2024-44240
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, …

Oct 28, 2024
CVE-2024-44237
5.5 MEDIUM

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Processing …

Oct 28, 2024
CVE-2024-44217
9.1 CRITICAL

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill …

Oct 28, 2024
CVE-2024-44216
5.5 MEDIUM

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app …

Oct 28, 2024
CVE-2024-44145
6.1 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical …

Oct 28, 2024
CVE-2024-30106
3.5 LOW

HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive …

Oct 28, 2024
CVE-2024-50496
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects …

Oct 28, 2024
CVE-2024-50495
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows Upload a Web Shell to a Web Server.This issue affects Plugin …

Oct 28, 2024
CVE-2024-48594
8.8 HIGH

File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.

Oct 28, 2024
CVE-2024-48356
9.8 CRITICAL

LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.

Oct 28, 2024
CVE-2024-48177
8.8 HIGH

MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.

Oct 28, 2024
CVE-2024-48107
6.5 MEDIUM

SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server …

Oct 28, 2024
CVE-2024-44302
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, …

Oct 28, 2024
CVE-2024-44301
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may …

Oct 28, 2024
CVE-2024-44297
6.5 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia …

Oct 28, 2024
CVE-2024-44296
5.4 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS …

Oct 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.