CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-47131
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-after-free after the TLS device goes down and up When a netdev with …

Mar 15, 2024
CVE-2021-47130
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool …

Mar 15, 2024
CVE-2021-47129
4.6 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: skip expectations for confirmed conntrack nft_ct_expect_obj_eval() calls nf_ct_ext_add() for a confirmed conntrack entry. …

Mar 15, 2024
CVE-2021-47128
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf, lockdown, audit: Fix buggy SELinux lockdown permission checks Commit 59438b46471a ("security,lockdown,selinux: implement SELinux lockdown") …

Mar 15, 2024
CVE-2021-47127
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: track AF_XDP ZC enabled queues in bitmap Commit c7a219048e45 ("ice: Remove xsk_buff_pool from VSI …

Mar 15, 2024
CVE-2021-47126
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions Reported by syzbot: HEAD commit: 90c911ad Merge tag …

Mar 15, 2024
CVE-2021-47125
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sch_htb: fix refcount leak in htb_parent_to_leaf_offload The commit ae81feb7338c ("sch_htb: fix null pointer dereference on …

Mar 15, 2024
CVE-2021-47124
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix link timeout refs WARNING: CPU: 0 PID: 10242 at lib/refcount.c:28 refcount_warn_saturate+0x15b/0x1a0 lib/refcount.c:28 RIP: …

Mar 15, 2024
CVE-2021-47123
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix ltout double free on completion race Always remove linked timeout on io_link_timeout_fn() from …

Mar 15, 2024
CVE-2021-47122
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in caif_device_notify In case of caif_enroll_dev() fail, allocated link_support won't …

Mar 15, 2024
CVE-2021-47121
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail, allocated link_support won't …

Mar 15, 2024
CVE-2021-47120
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: fix NULL-deref on disconnect Commit 9d7b18668956 ("HID: magicmouse: add support for Apple Magic …

Mar 15, 2024
CVE-2021-47119
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_fill_super Buffer head references must be released before calling kill_bdev(); …

Mar 15, 2024
CVE-2021-47118
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pid: take a reference when initializing `cad_pid` During boot, kernel_init_freeable() initializes `cad_pid` to the init …

Mar 15, 2024
CVE-2021-47117
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug on in ext4_es_cache_extent as ext4_split_extent_at failed We got follow bug_on when run …

Mar 15, 2024
CVE-2021-47116
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_mb_init_backend on error path. Fix a memory leak discovered by …

Mar 15, 2024
CVE-2021-47115

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 15, 2024
CVE-2021-47114
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption by fallocate When fallocate punches holes out of inode size, if …

Mar 15, 2024
CVE-2021-47113
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: abort in rename_exchange if we fail to insert the second ref Error injection stress …

Mar 15, 2024
CVE-2021-47112
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/kvm: Teardown PV features on boot CPU as well Various PV features (Async PF, PV …

Mar 15, 2024
CVE-2021-47111
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xen-netback: take a reference to the RX task thread Do this in order to prevent …

Mar 15, 2024
CVE-2021-47110
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/kvm: Disable kvmclock on all CPUs on shutdown Currenly, we disable kvmclock from machine_shutdown() hook …

Mar 15, 2024
CVE-2021-47109
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. …

Mar 15, 2024
CVE-2024-28848
8.8 HIGH

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎CompiledRule::validateExpression` method …

Mar 15, 2024
CVE-2024-28847
8.8 HIGH

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the …

Mar 15, 2024
CVE-2024-28255
9.8 CRITICAL

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles …

Mar 15, 2024
CVE-2024-28254
8.8 HIGH

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎AlertUtil::validateExpression` method …

Mar 15, 2024
CVE-2024-28253
9.4 CRITICAL

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also …

Mar 15, 2024
CVE-2024-28242
5.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. …

Mar 15, 2024
CVE-2024-27920
7.4 HIGH

projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the …

Mar 15, 2024
CVE-2024-27351
5.3 MEDIUM

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to …

Mar 15, 2024
CVE-2024-27100
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing …

Mar 15, 2024
CVE-2024-27085
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in …

Mar 15, 2024
CVE-2024-24827
5.3 MEDIUM

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker …

Mar 15, 2024
CVE-2024-24748
5.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category …

Mar 15, 2024
CVE-2023-7248
5.0 MEDIUM

Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by …

Mar 15, 2024
CVE-2024-28854
7.5 HIGH

tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can open 6.4 …

Mar 15, 2024
CVE-2024-28851
4.0 MEDIUM

The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of …

Mar 15, 2024
CVE-2024-28252
7.5 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. If you have a NetFraming based CoreWCF service, extra …

Mar 15, 2024
CVE-2023-7060
8.6 HIGH

Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the …

Mar 15, 2024
CVE-2023-51699
4.0 MEDIUM

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can …

Mar 15, 2024
CVE-2024-2537
4.4 MEDIUM

Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.

Mar 15, 2024
CVE-2024-2193
5.7 MEDIUM

A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can …

Mar 15, 2024
CVE-2024-2497
4.7 MEDIUM

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component …

Mar 15, 2024
CVE-2024-28404
8.0 HIGH

TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

Mar 15, 2024
CVE-2024-28401
5.4 MEDIUM

TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.

Mar 15, 2024
CVE-2023-7017
9.8 CRITICAL

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge …

Mar 15, 2024
CVE-2023-7009
8.2 HIGH

Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passed to the lock. These malicious commands, less …

Mar 15, 2024
CVE-2023-7007
8.2 HIGH

Sciener server does not validate connection requests from the GatewayG2, allowing an impersonation attack that provides the attacker the unlockKey field.

Mar 15, 2024
CVE-2023-7006
9.1 CRITICAL

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

Mar 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.