CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27394
7.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp: Fix Use-After-Free in tcp_ao_connect_init Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of …

May 14, 2024
CVE-2024-27393
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit …

May 14, 2024
CVE-2024-27282
6.6 MEDIUM

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary …

May 14, 2024
CVE-2024-27281
4.5 MEDIUM

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as …

May 14, 2024
CVE-2024-27280
9.8 CRITICAL

A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on …

May 14, 2024
CVE-2024-27269
6.8 MEDIUM

IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.

May 14, 2024
CVE-2024-27082
7.6 HIGH

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site …

May 14, 2024
CVE-2024-26517
9.1 CRITICAL

SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

May 14, 2024
CVE-2024-26306
5.9 MEDIUM

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This …

May 14, 2024
CVE-2024-25662
6.1 MEDIUM

Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.

May 14, 2024
CVE-2024-25641
9.1 CRITICAL

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows …

May 14, 2024
CVE-2024-25581
7.5 HIGH

When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an …

May 14, 2024
CVE-2024-24157
6.1 MEDIUM

Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

May 14, 2024
CVE-2024-23576
7.1 HIGH

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

May 14, 2024
CVE-2024-23473
8.6 HIGH

The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management …

May 14, 2024
CVE-2024-23236
5.5 MEDIUM

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.

May 14, 2024
CVE-2024-23229
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.5. A …

May 14, 2024
CVE-2024-22910
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.

May 14, 2024
CVE-2024-22774
7.8 HIGH

An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.

May 14, 2024
CVE-2024-22345
6.2 MEDIUM

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM …

May 14, 2024
CVE-2024-22344
6.1 MEDIUM

IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in …

May 14, 2024
CVE-2024-22343
4.0 MEDIUM

IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: …

May 14, 2024
CVE-2024-22064
8.3 HIGH

ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during …

May 14, 2024
CVE-2024-1693
4.3 MEDIUM

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category …

May 14, 2024
CVE-2024-1467
4.3 MEDIUM

The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

May 14, 2024
CVE-2024-1230
4.3 MEDIUM

The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or …

May 14, 2024
CVE-2024-1229
5.3 MEDIUM

The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions …

May 14, 2024
CVE-2024-1166
6.4 MEDIUM

The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hover Effects Widget in all …

May 14, 2024
CVE-2024-0445
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, …

May 14, 2024
CVE-2024-0100
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this …

May 14, 2024
CVE-2024-0098
5.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue …

May 14, 2024
CVE-2024-0097
7.5 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between …

May 14, 2024
CVE-2024-0096
7.5 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs …

May 14, 2024
CVE-2024-0088
5.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a …

May 14, 2024
CVE-2024-0087
9.0 CRITICAL

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, …

May 14, 2024
CVE-2023-6688
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google …

May 14, 2024
CVE-2023-6682
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

May 14, 2024
CVE-2023-6327
5.3 MEDIUM

The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in …

May 14, 2024
CVE-2023-5971
4.8 MEDIUM

The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege …

May 14, 2024
CVE-2023-5447
5.5 MEDIUM

Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics …

May 14, 2024
CVE-2023-5052
6.3 MEDIUM

vulnerability in Uniform Server Zero, version 10.2.5, consisting of an XSS through the /us_extra/phpinfo.php page. This vulnerability could allow a remote user to send a …

May 14, 2024
CVE-2023-52721
6.2 MEDIUM

The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.

May 14, 2024
CVE-2023-52720
4.1 MEDIUM

Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52719
7.1 HIGH

Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 14, 2024
CVE-2023-52656
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support …

May 14, 2024
CVE-2023-52655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet …

May 14, 2024
CVE-2023-52654
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for …

May 14, 2024
CVE-2023-52384
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52383
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-50718
6.5 MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.