CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Forward soft recovery errors to userspace As we discussed before[1], soft recovery should be …

Sep 4, 2024
CVE-2024-44960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: Check for unset descriptor Make sure the descriptor has been set before …

Sep 4, 2024
CVE-2024-44959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracefs: Use generic inode RCU for synchronizing freeing With structure layout randomization enabled for 'struct …

Sep 4, 2024
CVE-2024-44958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/smt: Fix unbalance sched_smt_present dec/inc I got the following warn report while doing stress test: …

Sep 4, 2024
CVE-2024-44957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Switch from mutex to spinlock for irqfds irqfd_wakeup() gets EPOLLHUP, when it is …

Sep 4, 2024
CVE-2024-44956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/preempt_fence: enlarge the fence critical section It is really easy to introduce subtle deadlocks in …

Sep 4, 2024
CVE-2024-44955

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 4, 2024
CVE-2024-44954
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: Fix racy access to midibuf There can be concurrent accesses to line6 midibuf …

Sep 4, 2024
CVE-2024-44953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix deadlock during RTC update There is a deadlock when runtime suspend …

Sep 4, 2024
CVE-2024-44952

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 4, 2024
CVE-2024-44951
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: fix TX fifo corruption Sometimes, when a packet is received on channel A …

Sep 4, 2024
CVE-2024-44950
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: fix invalid FIFO access with special register set When enabling access to the …

Sep 4, 2024
CVE-2024-44949
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parisc: fix a possible DMA corruption ARCH_DMA_MINALIGN was defined as 16 - this is too …

Sep 4, 2024
CVE-2024-44948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed variant …

Sep 4, 2024
CVE-2024-8417
3.1 LOW

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of …

Sep 4, 2024
CVE-2024-8416
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Sep 4, 2024
CVE-2024-45177
5.4 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent …

Sep 4, 2024
CVE-2024-8415
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Sep 4, 2024
CVE-2024-8414
4.3 MEDIUM

A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation …

Sep 4, 2024
CVE-2024-45174
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web …

Sep 4, 2024
CVE-2024-45170
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of …

Sep 4, 2024
CVE-2024-20503
5.5 MEDIUM

A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive information in cleartext on an affected system. This …

Sep 4, 2024
CVE-2024-20497
4.3 MEDIUM

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is …

Sep 4, 2024
CVE-2024-20469
6.0 MEDIUM

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the …

Sep 4, 2024
CVE-2024-20440
7.5 HIGH

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in …

Sep 4, 2024
CVE-2024-20439
9.8 CRITICAL KEV

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative …

Sep 4, 2024
CVE-2024-8412
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in LinuxOSsk Shakal-NG up to 1.3.3. Affected is an unknown function of the file comments/views.py. The …

Sep 4, 2024
CVE-2024-8391
7.5 HIGH

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This …

Sep 4, 2024
CVE-2024-45314
3.6 LOW

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. …

Sep 4, 2024
CVE-2024-45076
9.9 CRITICAL

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.

Sep 4, 2024
CVE-2024-45075
8.8 HIGH

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to …

Sep 4, 2024
CVE-2024-45074
6.5 MEDIUM

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing …

Sep 4, 2024
CVE-2024-45053
9.1 CRITICAL

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input …

Sep 4, 2024
CVE-2024-45052
5.3 MEDIUM

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an …

Sep 4, 2024
CVE-2024-45050
7.1 HIGH

Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where …

Sep 4, 2024
CVE-2024-44859
8.0 HIGH

Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.

Sep 4, 2024
CVE-2024-44821
5.3 MEDIUM

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a …

Sep 4, 2024
CVE-2024-44818
5.4 MEDIUM

Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.

Sep 4, 2024
CVE-2024-44817
8.8 HIGH

SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.

Sep 4, 2024
CVE-2024-44808
9.8 CRITICAL

An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.

Sep 4, 2024
CVE-2024-43405
7.4 HIGH

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature …

Sep 4, 2024
CVE-2024-43402
8.1 HIGH

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust …

Sep 4, 2024
CVE-2024-8418
7.5 HIGH

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An …

Sep 4, 2024
CVE-2024-8411
3.5 LOW

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument …

Sep 4, 2024
CVE-2024-8410
4.3 MEDIUM

A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown code of the file /abcd/opac/php/otros_sitios.php. The manipulation of …

Sep 4, 2024
CVE-2024-8409
4.3 MEDIUM

A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part of the file /common/show_image.php. The manipulation …

Sep 4, 2024
CVE-2024-7078
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection.This issue …

Sep 4, 2024
CVE-2024-7077
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Reflected XSS.This issue affects Semtek …

Sep 4, 2024
CVE-2024-7076
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection.This …

Sep 4, 2024
CVE-2024-45506
7.5 HIGH

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.