CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26762
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cxl/pci: Skip to handle RAS errors if CXL.mem device is detached The PCI AER model …

Apr 3, 2024
CVE-2024-26761
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window The …

Apr 3, 2024
CVE-2024-26760
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc …

Apr 3, 2024
CVE-2024-26759
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more …

Apr 3, 2024
CVE-2024-26758
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore suspended array in md_check_recovery() mddev_suspend() never stop sync_thread, hence it doesn't make …

Apr 3, 2024
CVE-2024-26757
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore read-only array in md_check_recovery() Usually if the array is not read-write, md_check_recovery() …

Apr 3, 2024
CVE-2024-26756
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md: Don't register sync_thread for reshape directly Currently, if reshape is interrupted, then reassemble the …

Apr 3, 2024
CVE-2024-26755
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape md_start_sync() will suspend the array if there …

Apr 3, 2024
CVE-2024-26754
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_genl_dump_pdp() The gtp_net_ops pernet operations structure for the subsystem …

Apr 3, 2024
CVE-2024-26753
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: virtio/akcipher - Fix stack overflow on memcpy sizeof(struct virtio_crypto_akcipher_session_para) is less than sizeof(struct virtio_crypto_op_ctrl_req::u), …

Apr 3, 2024
CVE-2024-26752
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: l2tp: pass correct message length to ip6_append_data l2tp_ip6_sendmsg needs to avoid accounting for the transport …

Apr 3, 2024
CVE-2024-26751
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: ep93xx: Add terminator to gpiod_lookup_table Without the terminator, if a con_id is passed to …

Apr 3, 2024
CVE-2024-26749
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fixed memory use after free at cdns3_gadget_ep_disable() ... cdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request); list_del_init(&priv_req->list); ... 'priv_req' …

Apr 3, 2024
CVE-2024-26748
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fix memory double free when handle zero packet 829 if (request->complete) { 830 …

Apr 3, 2024
CVE-2024-26747
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: roles: fix NULL pointer issue when put module's reference In current design, usb role …

Apr 3, 2024
CVE-2024-26744
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Support specifying the srpt_service_guid parameter Make loading ib_srpt with this parameter set work. The …

Apr 3, 2024
CVE-2024-26743
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/qedr: Fix qedr_create_user_qp error flow Avoid the following warning by making sure to free the …

Apr 3, 2024
CVE-2024-26742
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix disable_managed_interrupts Correct blk-mq registration issue with module parameter disable_managed_interrupts enabled. When we …

Apr 3, 2024
CVE-2024-26741
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished(). syzkaller reported a warning …

Apr 3, 2024
CVE-2024-26740
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: use the backlog for mirred ingress The test Davide added in commit ca22da2fbd69 …

Apr 3, 2024
CVE-2024-26739
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the …

Apr 3, 2024
CVE-2024-26738
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: DLPAR add doesn't completely initialize pci_controller When a PCI device is dynamically added, the …

Apr 3, 2024
CVE-2024-26737
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel The following race is possible between bpf_timer_cancel_and_free and …

Apr 3, 2024
CVE-2024-26736
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. …

Apr 3, 2024
CVE-2024-26735
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix possible use-after-free and null-ptr-deref The pernet operations structure for the subsystem must …

Apr 3, 2024
CVE-2024-26734
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: devlink: fix possible use-after-free and memory leaks in devlink_init() The pernet operations structure for the …

Apr 3, 2024
CVE-2024-26733
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) …

Apr 3, 2024
CVE-2024-26732
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: implement lockless setsockopt(SO_PEEK_OFF) syzbot reported a lockdep violation [1] involving af_unix support of SO_PEEK_OFF. …

Apr 3, 2024
CVE-2024-26731
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix NULL pointer dereference in sk_psock_verdict_data_ready() syzbot reported the following NULL pointer dereference …

Apr 3, 2024
CVE-2024-26730
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does …

Apr 3, 2024
CVE-2024-26729
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null pointer dereference in dc_dmub_srv Fixes potential null pointer dereference warnings in …

Apr 3, 2024
CVE-2024-26728
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix null-pointer dereference on edid reading Use i2c adapter when there isn't aux_mode in …

Apr 3, 2024
CVE-2024-26701

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 3, 2024
CVE-2024-23540
5.3 MEDIUM

The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix …

Apr 3, 2024
CVE-2024-20368
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery …

Apr 3, 2024
CVE-2024-20367
5.4 MEDIUM

A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) …

Apr 3, 2024
CVE-2024-20362
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker …

Apr 3, 2024
CVE-2024-20352
4.9 MEDIUM

A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform …

Apr 3, 2024
CVE-2024-20348
7.5 HIGH

A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to …

Apr 3, 2024
CVE-2024-20347
4.3 MEDIUM

A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary …

Apr 3, 2024
CVE-2024-20334
5.5 MEDIUM

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) …

Apr 3, 2024
CVE-2024-20332
5.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery …

Apr 3, 2024
CVE-2024-20310
6.1 MEDIUM

A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to …

Apr 3, 2024
CVE-2024-20302
5.4 MEDIUM

A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates …

Apr 3, 2024
CVE-2024-20283
4.3 MEDIUM

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due …

Apr 3, 2024
CVE-2024-20282
6.0 MEDIUM

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. …

Apr 3, 2024
CVE-2024-20281
7.5 HIGH

A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct …

Apr 3, 2024
CVE-2024-1180
8.0 HIGH

TP-Link Omada ER605 Access Control Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link …

Apr 3, 2024
CVE-2023-52641
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame() It is preferable to …

Apr 3, 2024
CVE-2023-52640
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix oob in ntfs_listxattr The length of name cannot exceed the space occupied by …

Apr 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.