CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45552
6.5 MEDIUM

In VeridiumID before 3.5.0, a stored cross-site scripting (XSS) vulnerability has been discovered in the admin portal that allows an authenticated attacker to take over …

Apr 3, 2024
CVE-2023-44040
6.1 MEDIUM

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker …

Apr 3, 2024
CVE-2023-44038
6.5 MEDIUM

In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated attacker to discover information about registered users via an LDAP injection attack.

Apr 3, 2024
CVE-2023-35812
5.3 MEDIUM

An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 …

Apr 3, 2024
CVE-2024-31393
4.3 MEDIUM

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < …

Apr 3, 2024
CVE-2024-31392
7.5 HIGH

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status …

Apr 3, 2024
CVE-2024-27673

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Apr 3, 2024
CVE-2023-44039
9.1 CRITICAL

In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) …

Apr 3, 2024
CVE-2024-28275
6.5 MEDIUM

Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive …

Apr 3, 2024
CVE-2024-26727
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not ASSERT() if the newly created subvolume already got read [BUG] There is …

Apr 3, 2024
CVE-2024-26726
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't drop extent_map for free space inode on write error While running the CI …

Apr 3, 2024
CVE-2024-26725
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dpll: fix possible deadlock during netlink dump operation Recently, I've been hitting following deadlock warning …

Apr 3, 2024
CVE-2024-26724
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DPLL, Fix possible use after free after delayed work timer triggers I managed to …

Apr 3, 2024
CVE-2024-26723
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix crash when adding interface under a lag There is a crash when adding …

Apr 3, 2024
CVE-2024-26722
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: rt5645: Fix deadlock in rt5645_jack_detect_work() There is a path in rt5645_jack_detect_work(), where rt5645->jd_mutex is …

Apr 3, 2024
CVE-2024-26721
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dsc: Fix the macro that calculates DSCC_/DSCA_ PPS reg address Commit bd077259d0a9 ("drm/i915/vdsc: Add function …

Apr 3, 2024
CVE-2024-26720

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 3, 2024
CVE-2024-26719
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nouveau: offload fence uevents work to workqueue This should break the deadlock between the fctx …

Apr 3, 2024
CVE-2024-26718
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm-crypt, dm-verity: disable tasklets Tasklets have an inherent problem with memory corruption. The function tasklet_action_common …

Apr 3, 2024
CVE-2024-26717
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid-of: fix NULL-deref on failed power up A while back the I2C HID implementation …

Apr 3, 2024
CVE-2024-26716
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: core: Prevent null pointer dereference in update_port_device_state Currently, the function update_port_device_state gets the usb_hub …

Apr 3, 2024
CVE-2024-26715
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix NULL pointer dereference in dwc3_gadget_suspend In current scenario if Plug-out and …

Apr 3, 2024
CVE-2024-26714
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: interconnect: qcom: sc8180x: Mark CO0 BCM keepalive The CO0 BCM needs to be up at …

Apr 3, 2024
CVE-2024-26713

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 3, 2024
CVE-2024-26712
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix addr error caused by page alignment In kasan_init_region, when k_start is not page …

Apr 3, 2024
CVE-2024-26711
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4130: zero-initialize clock init data The clk_init_data struct does not have all its …

Apr 3, 2024
CVE-2024-26710
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Limit KASAN thread size increase to 32KB KASAN is seen to increase stack usage, …

Apr 3, 2024
CVE-2024-26709
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the missing iommu_group_put() during platform domain attach The function spapr_tce_platform_iommu_attach_dev() is missing to …

Apr 3, 2024
CVE-2024-26708
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: really cope with fastopen race Fastopen and PM-trigger subflow shutdown can race, as reported …

Apr 3, 2024
CVE-2024-26707
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hsr: remove WARN_ONCE() in send_hsr_supervision_frame() Syzkaller reported [1] hitting a warning after failing to …

Apr 3, 2024
CVE-2024-26706
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Fix random data corruption from exception handler The current exception handler implementation, which assists …

Apr 3, 2024
CVE-2024-26705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU bringup When using hotplug and …

Apr 3, 2024
CVE-2024-26704
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks due to wrong extents moved_len In ext4_move_extents(), moved_len is only …

Apr 3, 2024
CVE-2024-26703
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/timerlat: Move hrtimer_init to timerlat_fd open() Currently, the timerlat's hrtimer is initialized at the first …

Apr 3, 2024
CVE-2024-26702
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC Recently, we encounter …

Apr 3, 2024
CVE-2024-26700
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix MST Null Ptr for RV The change try to fix below error specific …

Apr 3, 2024
CVE-2024-26699
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr [Why] There is a potential memory access violation while iterating …

Apr 3, 2024
CVE-2024-26698
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix race condition between netvsc_probe and netvsc_remove In commit ac5047671758 ("hv_netvsc: Disable NAPI before …

Apr 3, 2024
CVE-2024-26697
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix data corruption in dsync block recovery for small block sizes The helper function …

Apr 3, 2024
CVE-2024-26696
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix hang in nilfs_lookup_dirty_data_buffers() Syzbot reported a hang issue in migrate_pages_batch() called by mbind() …

Apr 3, 2024
CVE-2024-26695
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix null pointer dereference in __sev_platform_shutdown_locked The SEV platform device can be …

Apr 3, 2024
CVE-2024-26694
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix double-free bug The storage for the TLV PC register data wasn't done …

Apr 3, 2024
CVE-2024-26693
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix a crash when we run out of stations A DoS tool …

Apr 3, 2024
CVE-2024-26692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs …

Apr 3, 2024
CVE-2024-26691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix circular locking dependency The rule inside kvm enforces that the vcpu->mutex is …

Apr 3, 2024
CVE-2024-26690
6.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, …

Apr 3, 2024
CVE-2024-26689
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught …

Apr 3, 2024
CVE-2024-26688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super When configuring a hugetlb filesystem via the fsconfig() …

Apr 3, 2024
CVE-2024-26687
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen/events: close evtchn after mapping cleanup shutdown_pirq and startup_pirq are not taking the irq_mapping_update_lock because …

Apr 3, 2024
CVE-2024-26686
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats lock_task_sighand() can trigger a hard lockup. …

Apr 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.