CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-47164
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix null deref accessing lag dev It could be the lag dev is null …

Mar 25, 2024
CVE-2021-47163
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tipc: wait and exit until all work queues are done On some host, a crash …

Mar 25, 2024
CVE-2021-47162
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tipc: skb_linearize the head skb when reassembling msgs It's not a good idea to append …

Mar 25, 2024
CVE-2021-47161
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-dspi: Fix a resource leak in an error handling path 'dspi_request_dma()' should be undone …

Mar 25, 2024
CVE-2021-47160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when …

Mar 25, 2024
CVE-2021-47159
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix a crash if ->get_sset_count() fails If ds->ops->get_sset_count() fails then it "count" is …

Mar 25, 2024
CVE-2021-47158
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: add error handling in sja1105_setup() If any of sja1105_static_config_load(), sja1105_clocking_setup() or sja1105_devlink_setup() …

Mar 25, 2024
CVE-2024-25964
5.3 MEDIUM

Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of …

Mar 25, 2024
CVE-2021-47153
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Don't generate an interrupt on bus reset Now that the i2c-i801 driver supports …

Mar 25, 2024
CVE-2021-47152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data stream corruption Maxim reported several issues when forcing a TCP transparent proxy …

Mar 25, 2024
CVE-2021-47151
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: interconnect: qcom: bcm-voter: add a missing of_node_put() Add a missing of_node_put() in of_bcm_voter_get() to avoid …

Mar 25, 2024
CVE-2021-47150
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fec: fix the potential memory leak in fec_enet_init() If the memory allocated for cbd_base …

Mar 25, 2024
CVE-2021-47149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fujitsu: fix potential null-ptr-deref In fmvj18x_get_hwinfo(), if ioremap fails there will be NULL pointer …

Mar 25, 2024
CVE-2021-47148
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix a buffer overflow in otx2_set_rxfh_context() This function is called from ethtool_set_rxfh() and "*rss_context" …

Mar 25, 2024
CVE-2021-47147
6.2 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix a resource leak in an error handling path If an error occurs …

Mar 25, 2024
CVE-2021-47146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mld: fix panic in mld_newpack() mld_newpack() doesn't allow to allocate high order page, only order-0 …

Mar 25, 2024
CVE-2021-47145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not BUG_ON in link_to_fixup_dir While doing error injection testing I got the following …

Mar 25, 2024
CVE-2021-47144

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 25, 2024
CVE-2021-47143
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: remove device from smcd_dev_list after failed device_add() If the device_add() for a smcd_dev fails, …

Mar 25, 2024
CVE-2021-47142
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix a use-after-free looks like we forget to set ttm->sg to NULL. Hit panic …

Mar 25, 2024
CVE-2021-47141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs. When freeing notification blocks, we index priv->msix_vectors. …

Mar 25, 2024
CVE-2021-47140
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Clear DMA ops when switching domain Since commit 08a27c1c3ecf ("iommu: Add support to change …

Mar 25, 2024
CVE-2021-47139
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: put off calling register_netdev() until client initialize complete Currently, the netdevice is registered …

Mar 25, 2024
CVE-2021-47138
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having the server TID base can …

Mar 25, 2024
CVE-2021-47137
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or …

Mar 25, 2024
CVE-2021-47136
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: zero-initialize tc skb extension on allocation Function skb_ext_add() doesn't initialize created skb extension with …

Mar 25, 2024
CVE-2024-30187
5.3 MEDIUM

Anope before 2.0.15 does not prevent resetting the password of a suspended account.

Mar 25, 2024
CVE-2024-2863
5.3 MEDIUM

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

Mar 25, 2024
CVE-2024-2862
9.1 CRITICAL

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

Mar 25, 2024
CVE-2024-29216
6.1 MEDIUM

Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege …

Mar 25, 2024
CVE-2024-24899
7.2 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is …

Mar 25, 2024
CVE-2024-24897
8.1 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with …

Mar 25, 2024
CVE-2024-24892
8.1 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, …

Mar 25, 2024
CVE-2024-24890
7.8 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is …

Mar 25, 2024
CVE-2021-33632
7.0 HIGH

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program …

Mar 25, 2024
CVE-2020-36826
3.5 LOW

A vulnerability was found in AwesomestCode LiveBot. It has been classified as problematic. Affected is the function parseSend of the file js/parseMessage.js. The manipulation leads …

Mar 25, 2024
CVE-2022-36407
9.9 CRITICAL

Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi …

Mar 25, 2024
CVE-2024-29009
6.1 MEDIUM

Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to perform unintended …

Mar 25, 2024
CVE-2024-21865
6.5 MEDIUM

HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and …

Mar 25, 2024
CVE-2024-21505
7.5 HIGH

Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An …

Mar 25, 2024
CVE-2024-1962
8.8 HIGH

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins …

Mar 25, 2024
CVE-2024-1564
4.3 MEDIUM

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post …

Mar 25, 2024
CVE-2024-1232
4.8 MEDIUM

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins …

Mar 25, 2024
CVE-2024-1231
6.8 MEDIUM

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins …

Mar 25, 2024
CVE-2023-37886
5.4 MEDIUM

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

Mar 25, 2024
CVE-2023-37885
4.3 MEDIUM

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

Mar 25, 2024
CVE-2023-33923
4.3 MEDIUM

Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: …

Mar 25, 2024
CVE-2023-30480
4.3 MEDIUM

Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.

Mar 25, 2024
CVE-2024-29071
8.8 HIGH

HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.

Mar 25, 2024
CVE-2024-28041
8.8 HIGH

HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.

Mar 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.