CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33791
4.6 MEDIUM

A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

May 3, 2024
CVE-2024-33789
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

May 3, 2024
CVE-2024-31636
3.9 LOW

An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.

May 3, 2024
CVE-2024-30851
6.5 MEDIUM

Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.php component.

May 3, 2024
CVE-2024-28519
7.8 HIGH

A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privilege escalation for low-privileged users.

May 3, 2024
CVE-2021-20450
4.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get …

May 3, 2024
CVE-2020-4874
5.9 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

May 3, 2024
CVE-2024-34449
6.1 MEDIUM

Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

May 3, 2024
CVE-2024-34447
7.5 HIGH

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) …

May 3, 2024
CVE-2024-33398
7.5 HIGH

There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account …

May 3, 2024
CVE-2023-37407
8.8 HIGH

IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force …

May 3, 2024
CVE-2022-48703
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a …

May 3, 2024
CVE-2022-48702
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc() The voice allocator sometimes begins allocating …

May 3, 2024
CVE-2022-48701
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() There may be a bad USB audio …

May 3, 2024
CVE-2022-48700

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 3, 2024
CVE-2022-48699
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/debug: fix dentry leak in update_sched_domain_debugfs Kuyo reports that the pattern of using debugfs_remove(debugfs_lookup()) leaks …

May 3, 2024
CVE-2022-48698
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix memory leak when using debugfs_lookup() When calling debugfs_lookup() the result must have dput() …

May 3, 2024
CVE-2022-48697
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a use-after-free Fix the following use-after-free complaint triggered by blktests nvme/004: BUG: KASAN: …

May 3, 2024
CVE-2022-48696
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regmap: spi: Reserve space for register address/padding Currently the max_raw_read and max_raw_write limits in regmap_spi …

May 3, 2024
CVE-2024-3480
2.8 LOW

An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.

May 3, 2024
CVE-2024-3479
2.8 LOW

An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.

May 3, 2024
CVE-2024-34446
7.5 HIGH

Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and …

May 3, 2024
CVE-2024-33844
7.5 HIGH

The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between …

May 3, 2024
CVE-2024-29417
8.4 HIGH

Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.

May 3, 2024
CVE-2022-48694
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix drain SQ hang with no completion SW generated completions for outstanding WRs posted …

May 3, 2024
CVE-2022-48693
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs In brcmstb_pm_probe(), there are two …

May 3, 2024
CVE-2022-48692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Set scmnd->result only when scmnd is not NULL This change fixes the following kernel …

May 3, 2024
CVE-2022-48691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clean up hook list when offload flags check fails splice back the hook …

May 3, 2024
CVE-2022-48689
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp: TX zerocopy should not sense pfmemalloc status We got a recent syzbot report [1] …

May 3, 2024
CVE-2022-48688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix kernel crash during module removal The driver incorrectly frees client instance and subsequent …

May 3, 2024
CVE-2022-48687
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix out-of-bounds read when setting HMAC data. The SRv6 layer allows defining HMAC …

May 3, 2024
CVE-2022-48686
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop …

May 3, 2024
CVE-2022-48675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix a nested dead lock as part of ODP flow Fix a nested dead …

May 3, 2024
CVE-2022-48674
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: erofs: fix pcluster use-after-free on UP platforms During stress testing with CONFIG_SMP disabled, KASAN reports …

May 3, 2024
CVE-2022-48673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in link clear After modifying the QP to …

May 3, 2024
CVE-2022-48672
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") …

May 3, 2024
CVE-2022-48671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for …

May 3, 2024
CVE-2022-48670
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which …

May 3, 2024
CVE-2024-3109
6.3 MEDIUM

A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker …

May 3, 2024
CVE-2024-3108
5.5 MEDIUM

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device …

May 3, 2024
CVE-2024-1395
6.7 MEDIUM

Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing …

May 3, 2024
CVE-2024-1067
7.4 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

May 3, 2024
CVE-2023-6363
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

May 3, 2024
CVE-2023-41830
6.5 MEDIUM

An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.

May 3, 2024
CVE-2023-41828
4.4 MEDIUM

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.

May 3, 2024
CVE-2023-41826
5.1 MEDIUM

A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without …

May 3, 2024
CVE-2023-41825
2.8 LOW

A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.

May 3, 2024
CVE-2023-41824
2.8 LOW

An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and …

May 3, 2024
CVE-2023-41823
4.4 MEDIUM

An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.

May 3, 2024
CVE-2023-41822
4.8 MEDIUM

An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.

May 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.