CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26641
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed …

Mar 18, 2024
CVE-2024-26640
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity checks to rx zerocopy TCP rx zerocopy intent is to map pages …

Mar 18, 2024
CVE-2024-26639

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 18, 2024
CVE-2024-26638
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nbd: always initialize struct msghdr completely syzbot complains that msg->msg_get_inq value can be uninitialized [1] …

Mar 18, 2024
CVE-2024-26637
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: rely on mac80211 debugfs handling for vif mac80211 started to delete debugfs entries …

Mar 18, 2024
CVE-2024-26636
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: llc: make llc_ui_sendmsg() more robust against bonding changes syzbot was able to trick llc_ui_sendmsg(), allocating …

Mar 18, 2024
CVE-2024-26635
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below. [0] llc supports ETH_P_802_2 …

Mar 18, 2024
CVE-2024-26634
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fix removing a namespace with conflicting altnames Mark reports a BUG() when a net …

Mar 18, 2024
CVE-2024-26633
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() syzbot pointed out [1] that NEXTHDR_FRAGMENT handling is broken. …

Mar 18, 2024
CVE-2024-26632
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: Fix iterating over an empty bio with bio_for_each_folio_all If the bio contains no data, …

Mar 18, 2024
CVE-2024-26631
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work idev->mc_ifc_count can be written over without proper …

Mar 18, 2024
CVE-2024-1013
7.8 HIGH

An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue …

Mar 18, 2024
CVE-2023-52619
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Fix crash when setting number of cpus to an odd number When the number …

Mar 18, 2024
CVE-2023-52618
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block/rnbd-srv: Check for unlikely string overflow Since "dev_search_path" can technically be as large as PATH_MAX, …

Mar 18, 2024
CVE-2023-52617
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: switchtec: Fix stdev_release() crash after surprise hot remove A PCI device hot removal may …

Mar 18, 2024
CVE-2023-52616
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init When the mpi_ec_ctx structure is initialized, …

Mar 18, 2024
CVE-2023-52615
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock …

Mar 18, 2024
CVE-2023-52614
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple …

Mar 18, 2024
CVE-2023-52613
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drivers/thermal/loongson2_thermal: Fix incorrect PTR_ERR() judgment PTR_ERR() returns -ENODEV when thermal-zones are undefined, and we need …

Mar 18, 2024
CVE-2023-52612
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked before …

Mar 18, 2024
CVE-2023-52611
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: sdio: Honor the host max_req_size in the RX path Lukas reports skb_over_panic errors …

Mar 18, 2024
CVE-2023-52610
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix skb leak and crash on ooo frags act_ct adds skb->users before defragmentation. …

Mar 18, 2024
CVE-2023-52609
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: fix race between mmput() and do_exit() Task A calls binder_update_page_range() to allocate and insert …

Mar 18, 2024
CVE-2024-1606
4.6 MEDIUM

Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. …

Mar 18, 2024
CVE-2024-1605
6.6 MEDIUM

BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to …

Mar 18, 2024
CVE-2024-1604
6.4 MEDIUM

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes …

Mar 18, 2024
CVE-2024-28039
5.8 MEDIUM

Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, …

Mar 18, 2024
CVE-2024-28128
6.1 MEDIUM

Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web …

Mar 18, 2024
CVE-2024-28125
9.8 CRITICAL

FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a …

Mar 18, 2024
CVE-2024-27974
6.3 MEDIUM

Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In …

Mar 18, 2024
CVE-2024-23604
6.1 MEDIUM

Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of …

Mar 18, 2024
CVE-2024-22475
6.1 MEDIUM

Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. allows a remote unauthenticated attacker to …

Mar 18, 2024
CVE-2024-21824
5.3 MEDIUM

Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, …

Mar 18, 2024
CVE-2024-29156
6.5 MEDIUM

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied …

Mar 18, 2024
CVE-2024-29154
7.4 HIGH

danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.

Mar 18, 2024
CVE-2024-29151
9.1 CRITICAL

Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.

Mar 18, 2024
CVE-2021-47157
9.8 CRITICAL

The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

Mar 18, 2024
CVE-2021-47156
6.5 MEDIUM

The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers …

Mar 18, 2024
CVE-2021-47155
9.1 CRITICAL

The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to …

Mar 18, 2024
CVE-2021-47154
6.3 MEDIUM

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some …

Mar 18, 2024
CVE-2018-25099
9.8 CRITICAL

In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

Mar 18, 2024
CVE-2024-28745
3.3 LOW

Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing another app installed on the user's device to …

Mar 18, 2024
CVE-2024-27757
6.1 MEDIUM

flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS. The reporter indicates that this product "ceased its development as of February 2024."

Mar 18, 2024
CVE-2024-2581
8.8 HIGH

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of …

Mar 18, 2024
CVE-2024-2577
7.3 HIGH

A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. …

Mar 18, 2024
CVE-2024-24539
5.3 MEDIUM

FusionPBX before 5.2.0 does not validate a session.

Mar 18, 2024
CVE-2022-47037
7.5 HIGH

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

Mar 18, 2024
CVE-2022-47036
9.8 CRITICAL

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. …

Mar 18, 2024
CVE-2024-2576
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. …

Mar 18, 2024
CVE-2024-2575
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality …

Mar 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.