CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26685
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential bug in end_buffer_async_write According to a syzbot report, end_buffer_async_write(), which handles the …

Apr 3, 2024
CVE-2023-5755

Rejected reason: **REJECT** Duplicate of CVE-2023-46784. Please refer to CVE-2023-46784.

Apr 3, 2024
CVE-2023-52639
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: fix race during shadow creation Right now it is possible to see …

Apr 3, 2024
CVE-2023-52638
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: j1939: prevent deadlock by changing j1939_socks_lock to rwlock The following 3 locks would race …

Apr 3, 2024
CVE-2023-52637
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: j1939: Fix UAF in j1939_sk_match_filter during setsockopt(SO_J1939_FILTER) Lock jsk->sk to prevent UAF when setsockopt(..., …

Apr 3, 2024
CVE-2024-3259
6.3 MEDIUM

A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 3, 2024
CVE-2024-31420
6.5 MEDIUM

A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node …

Apr 3, 2024
CVE-2024-31419
4.3 MEDIUM

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled …

Apr 3, 2024
CVE-2024-27201
4.9 MEDIUM

An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of …

Apr 3, 2024
CVE-2024-24976
4.9 MEDIUM

A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted …

Apr 3, 2024
CVE-2024-22178
4.9 MEDIUM

A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of …

Apr 3, 2024
CVE-2024-21870
4.9 MEDIUM

A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network …

Apr 3, 2024
CVE-2024-0394
7.8 HIGH

Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM …

Apr 3, 2024
CVE-2024-3258
6.3 MEDIUM

A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 3, 2024
CVE-2024-3257
6.3 MEDIUM

A vulnerability was found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Apr 3, 2024
CVE-2024-3256
6.3 MEDIUM

A vulnerability has been found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 3, 2024
CVE-2024-30572
8.0 HIGH

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.

Apr 3, 2024
CVE-2024-30571
7.5 HIGH

An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

Apr 3, 2024
CVE-2024-30570
5.3 MEDIUM

An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

Apr 3, 2024
CVE-2024-30569
7.5 HIGH

An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

Apr 3, 2024
CVE-2024-30568
9.8 CRITICAL

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

Apr 3, 2024
CVE-2024-27254
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a …

Apr 3, 2024
CVE-2024-25096
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.

Apr 3, 2024
CVE-2024-25046
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user …

Apr 3, 2024
CVE-2024-25030
6.2 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a …

Apr 3, 2024
CVE-2024-24707
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.

Apr 3, 2024
CVE-2024-22360
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on …

Apr 3, 2024
CVE-2023-52296
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function …

Apr 3, 2024
CVE-2023-38729
6.8 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with …

Apr 3, 2024
CVE-2023-25699
9.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue …

Apr 3, 2024
CVE-2024-3255
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Internship Portal Management System 1.0. Affected is an unknown function of the file admin/edit_admin_query.php. …

Apr 3, 2024
CVE-2024-3254
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Internship Portal Management System 1.0. This issue affects some unknown processing of the …

Apr 3, 2024
CVE-2024-31390
9.9 CRITICAL

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

Apr 3, 2024
CVE-2024-31380
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This …

Apr 3, 2024
CVE-2024-29477
8.8 HIGH

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute …

Apr 3, 2024
CVE-2024-28782
6.3 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can …

Apr 3, 2024
CVE-2024-27972
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= …

Apr 3, 2024
CVE-2024-27951
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This …

Apr 3, 2024
CVE-2024-27191
8.5 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion.This issue affects Slivery Extender: from n/a through …

Apr 3, 2024
CVE-2024-25918
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

Apr 3, 2024
CVE-2024-3253
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Internship Portal Management System 1.0. This vulnerability affects unknown code of the file admin/add_admin.php. The manipulation …

Apr 3, 2024
CVE-2024-3252
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This affects an unknown part of the file admin/check_admin.php. The …

Apr 3, 2024
CVE-2024-3251
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 3, 2024
CVE-2024-0172
7.9 HIGH

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, …

Apr 3, 2024
CVE-2024-29734
7.8 HIGH

Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Libraries. As a result, …

Apr 3, 2024
CVE-2024-28589
6.7 MEDIUM

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges …

Apr 3, 2024
CVE-2023-35764
5.3 MEDIUM

Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.

Apr 3, 2024
CVE-2023-34423
6.1 MEDIUM

Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web …

Apr 3, 2024
CVE-2024-28515
9.8 CRITICAL

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

Apr 3, 2024
CVE-2024-24506
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter …

Apr 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.