CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20304
8.6 HIGH

A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP …

Sep 11, 2024
CVE-2024-7312
6.1 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from …

Sep 11, 2024
CVE-2024-5760
7.8 HIGH

The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This …

Sep 11, 2024
CVE-2024-46672
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion wpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA …

Sep 11, 2024
CVE-2024-45030
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well …

Sep 11, 2024
CVE-2024-45029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: Do not mark ACPI devices as irq safe On ACPI machines, the tegra …

Sep 11, 2024
CVE-2024-45028
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails …

Sep 11, 2024
CVE-2024-45027
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup() If xhci_mem_init() fails, it calls into …

Sep 11, 2024
CVE-2024-45026
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) …

Sep 11, 2024
CVE-2024-45025
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the …

Sep 11, 2024
CVE-2024-45024
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb vs. core-mm PT locking We recently made GUP's common page table walking …

Sep 11, 2024
CVE-2024-45023
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array with slow disk read_balance() will avoid reading from …

Sep 11, 2024
CVE-2024-45022
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 The __vmap_pages_range_noflush() …

Sep 11, 2024
CVE-2024-45021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memcg_write_event_control(): fix a user-triggerable oops we are *not* guaranteed that anything past the terminating NUL …

Sep 11, 2024
CVE-2024-45020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a kernel verifier crash in stacksafe() Daniel Hodges reported a kernel verifier crash …

Sep 11, 2024
CVE-2024-45019
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take state lock during tx timeout reporter mlx5e_safe_reopen_channels() requires the state lock taken. The …

Sep 11, 2024
CVE-2024-45018
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: initialise extack before use Fix missing initialisation of extack in flow offload.

Sep 11, 2024
CVE-2024-45017
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix IPsec RoCE MPV trace call Prevent the call trace below from happening, by …

Sep 11, 2024
CVE-2024-45016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netem: fix return value if duplicate enqueue fails There is a bug in netem_enqueue() introduced …

Sep 11, 2024
CVE-2024-45015
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable() For cases where the crtc's connectors_changed was set …

Sep 11, 2024
CVE-2024-45014
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/boot: Avoid possible physmem_info segment corruption When physical memory for the kernel image is allocated …

Sep 11, 2024
CVE-2024-45013
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme: move stopping keep-alive into nvme_uninit_ctrl() Commit 4733b65d82bd ("nvme: start keep-alive after admin queue setup") …

Sep 11, 2024
CVE-2024-45012
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator Currently, enabling SG_DEBUG in the kernel will cause nouveau to …

Sep 11, 2024
CVE-2024-45011
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing device Ensure, as the driver probes the device, …

Sep 11, 2024
CVE-2024-45010
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available Adding the following warning ... WARN_ON_ONCE(msk->pm.local_addr_used == …

Sep 11, 2024
CVE-2024-45009
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ req Adding the following warning ... WARN_ON_ONCE(msk->pm.add_addr_accepted == …

Sep 11, 2024
CVE-2024-44851
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a …

Sep 11, 2024
CVE-2024-44466
9.8 CRITICAL

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

Sep 11, 2024
CVE-2024-41868
5.5 MEDIUM

Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Sep 11, 2024
CVE-2024-39378
7.8 HIGH

Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Sep 11, 2024
CVE-2024-8306
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries …

Sep 11, 2024
CVE-2024-4465
6.0 MEDIUM

An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. …

Sep 11, 2024
CVE-2024-43793
6.3 MEDIUM

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability …

Sep 11, 2024
CVE-2024-8646
6.1 MEDIUM

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the …

Sep 11, 2024
CVE-2024-8642
8.1 HIGH

In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can …

Sep 11, 2024
CVE-2024-8639
8.8 HIGH

Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Sep 11, 2024
CVE-2024-8638
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Sep 11, 2024
CVE-2024-8637
8.8 HIGH

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a …

Sep 11, 2024
CVE-2024-8636
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 11, 2024
CVE-2024-7805

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 11, 2024
CVE-2024-27115
9.8 CRITICAL

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files …

Sep 11, 2024
CVE-2024-27114
9.8 CRITICAL

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker …

Sep 11, 2024
CVE-2024-27113
9.8 CRITICAL

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting …

Sep 11, 2024
CVE-2024-27112
9.8 CRITICAL

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use …

Sep 11, 2024
CVE-2024-6091
9.8 CRITICAL

A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to …

Sep 11, 2024
CVE-2024-45790
9.8 CRITICAL

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker …

Sep 11, 2024
CVE-2024-7609
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before …

Sep 11, 2024
CVE-2024-5416
5.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of …

Sep 11, 2024
CVE-2024-45789
4.3 MEDIUM

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. …

Sep 11, 2024
CVE-2024-45788
7.5 HIGH

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.