CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed The driver creates /sys/kernel/debug/dri/0/mob_ttm even when the …

May 1, 2024
CVE-2024-26939
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/i915/vma: Fix UAF on destroy against retire race Object debugging tools were sporadically reporting illegal …

May 1, 2024
CVE-2024-26938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() If we have no VBT, or the VBT didn't declare …

May 1, 2024
CVE-2024-26937
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Reset queue_priority_hint on parking Originally, with strict in order execution, we could complete execution …

May 1, 2024
CVE-2024-26936
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf …

May 1, 2024
CVE-2024-26935
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix unremoved procfs host directory regression Commit fc663711b944 ("scsi: core: Remove the /proc/scsi/${proc_name} …

May 1, 2024
CVE-2024-26934
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix deadlock in usb_deauthorize_interface() Among the attribute file callback routines in drivers/usb/core/sysfs.c, the …

May 1, 2024
CVE-2024-26933
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix deadlock in port "disable" sysfs attribute The show and store callback routines …

May 1, 2024
CVE-2024-26932
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: fix double-free issue in tcpm_port_unregister_pd() When unregister pd capabilitie in tcpm, KASAN …

May 1, 2024
CVE-2024-26931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix command flush on cable pull System crash due to command failed to …

May 1, 2024
CVE-2024-26930
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of the ha->vp_map pointer Coverity scan reported potential risk of …

May 1, 2024
CVE-2024-26929

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 1, 2024
CVE-2023-52648
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Unmap the surface before resetting it on a plane state Switch to a new …

May 1, 2024
CVE-2023-52647
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: Check whether crossbar pad is non-NULL before access When translating source to …

May 1, 2024
CVE-2024-28979
5.1 MEDIUM

Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with …

May 1, 2024
CVE-2024-28978
5.2 MEDIUM

Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerability, leading to …

May 1, 2024
CVE-2024-33768
9.8 CRITICAL

lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.

May 1, 2024
CVE-2024-33767
5.0 MEDIUM

lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source.

May 1, 2024
CVE-2024-33766
5.3 MEDIUM

lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.

May 1, 2024
CVE-2024-33764
5.5 MEDIUM

lunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h.

May 1, 2024
CVE-2024-33763
7.5 HIGH

lunasvg v2.3.9 was discovered to contain a stack-buffer-underflow at lunasvg/source/layoutcontext.cpp.

May 1, 2024
CVE-2024-4369
6.8 MEDIUM

An information disclosure flaw was found in OpenShift's internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod …

May 1, 2024
CVE-2024-4349
7.3 HIGH

A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 30, 2024
CVE-2024-4192
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage …

Apr 30, 2024
CVE-2024-34149
6.3 MEDIUM

In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a different issue than CVE-2023-50428. NOTE: some parties …

Apr 30, 2024
CVE-2024-32970
7.1 HIGH

Phlex is a framework for building object-oriented views in Ruby. In affected versions there is a potential cross-site scripting (XSS) vulnerability that can be exploited …

Apr 30, 2024
CVE-2024-4348
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the …

Apr 30, 2024
CVE-2024-29466
8.8 HIGH

Directory Traversal vulnerability in lsgwr spring boot online exam v.0.9 allows an attacker to execute arbitrary code via the FileTransUtil.java component.

Apr 30, 2024
CVE-2024-3746
5.5 MEDIUM

The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite …

Apr 30, 2024
CVE-2024-33437
7.5 HIGH

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style Rules.

Apr 30, 2024
CVE-2024-33436
5.3 MEDIUM

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables

Apr 30, 2024
CVE-2024-33383
7.5 HIGH

Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath …

Apr 30, 2024
CVE-2024-33371
6.1 MEDIUM

Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.

Apr 30, 2024
CVE-2024-33332
7.5 HIGH

An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.

Apr 30, 2024
CVE-2024-29384
7.5 HIGH

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.

Apr 30, 2024
CVE-2024-3411
9.1 CRITICAL

Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID …

Apr 30, 2024
CVE-2024-34088
7.5 HIGH

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases …

Apr 30, 2024
CVE-2024-28269
7.2 HIGH

ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to upload of malicious …

Apr 30, 2024
CVE-2024-26331
7.5 HIGH

ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a …

Apr 30, 2024
CVE-2024-22546
6.4 MEDIUM

TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network …

Apr 30, 2024
CVE-2023-50059
5.3 MEDIUM

An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks …

Apr 30, 2024
CVE-2023-50053
7.6 HIGH

An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Foundation, the signed message …

Apr 30, 2024
CVE-2023-49473
9.8 CRITICAL

Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorrect Access Control.

Apr 30, 2024
CVE-2020-27478
7.1 HIGH

Cross Site Scripting vulnerability found in Simplcommerce v.40734964b0811f3cbaf64b6dac261683d256f961 thru 3103357200c70b4767986544e01b19dbf11505a7 allows a remote attacker to execute arbitrary code via a crafted script to the search …

Apr 30, 2024
CVE-2024-33832
6.3 MEDIUM

OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=api&method=get_link_info.

Apr 30, 2024
CVE-2024-33831
7.4 HIGH

A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML …

Apr 30, 2024
CVE-2024-33103
6.1 MEDIUM

An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. …

Apr 30, 2024
CVE-2024-33102
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 30, 2024
CVE-2024-33101
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 30, 2024
CVE-2023-36268

Rejected reason: DoS issues, or unexploitable crashes, are out of scope for vulnerabilities.

Apr 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.