CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26616
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: scrub: avoid use-after-free when chunk length is not 64K aligned [BUG] There is a …

Mar 11, 2024
CVE-2024-26615
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix illegal rmb_desc access in SMC-D connection dump A crash was found when dumping …

Mar 11, 2024
CVE-2024-26614
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program …

Mar 11, 2024
CVE-2024-26613

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 11, 2024
CVE-2024-26612
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs, fscache: Prevent Oops in fscache_put_cache() This function dereferences "cache" and then checks if it's …

Mar 11, 2024
CVE-2024-26611
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of multi-buffer BPF helpers for ZC XDP Currently when packet is shrunk …

Mar 11, 2024
CVE-2024-26610
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means …

Mar 11, 2024
CVE-2024-26609

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 11, 2024
CVE-2024-26608
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix global oob in ksmbd_nl_policy Similar to a reported issue (check the commit b33fb5b801c6 …

Mar 11, 2024
CVE-2024-1487
5.4 MEDIUM

The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as …

Mar 11, 2024
CVE-2024-1290
6.5 MEDIUM

The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, …

Mar 11, 2024
CVE-2024-1279
4.3 MEDIUM

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

Mar 11, 2024
CVE-2024-1273
6.1 MEDIUM

The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to …

Mar 11, 2024
CVE-2024-1068
7.2 HIGH

The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a …

Mar 11, 2024
CVE-2024-0561
5.4 MEDIUM

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which …

Mar 11, 2024
CVE-2024-0559
6.5 MEDIUM

The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which …

Mar 11, 2024
CVE-2023-7247
4.9 MEDIUM

The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.

Mar 11, 2024
CVE-2023-6444
5.3 MEDIUM

The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated …

Mar 11, 2024
CVE-2023-52498
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PM: sleep: Fix possible deadlocks in core system-wide PM code It is reported that in …

Mar 11, 2024
CVE-2023-52495
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink_altmode: fix port sanity check The PMIC GLINK altmode driver currently supports at …

Mar 11, 2024
CVE-2023-52494
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Add alignment check for event ring read pointer Though we do check …

Mar 11, 2024
CVE-2023-52493
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Drop chan lock before queuing buffers Ensure read and write locks for …

Mar 11, 2024
CVE-2023-52492
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fix NULL pointer in channel unregistration function __dma_async_device_channel_register() can fail. In case of failure, …

Mar 11, 2024
CVE-2023-52491
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_run In …

Mar 11, 2024
CVE-2023-52490
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: migrate: fix getting incorrect page mapping during page migration When running stress-ng testing, we …

Mar 11, 2024
CVE-2023-52489
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/sparsemem: fix race in accessing memory_section->usage The below race is observed on a PFN which …

Mar 11, 2024
CVE-2023-52488
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: convert from _raw_ to _noinc_ regmap functions for FIFO The SC16IS7XX IC supports …

Mar 11, 2024
CVE-2023-52487
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix peer flow lists handling The cited change refactored mlx5e_tc_del_fdb_peer_flow() to only clear DUP …

Mar 11, 2024
CVE-2023-52486
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm: Don't unref the same fb many times by mistake due to deadlock handling If …

Mar 11, 2024
CVE-2024-23717
8.8 HIGH

In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation …

Mar 11, 2024
CVE-2024-1696
7.8 HIGH

In Santesoft Sante FFT Imaging versions 1.4.1 and prior once a user opens a malicious DCM file on affected FFT Imaging installations, a local attacker …

Mar 11, 2024
CVE-2024-0053
3.3 LOW

In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information …

Mar 11, 2024
CVE-2024-0052
3.3 LOW

In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission check. This could lead to local …

Mar 11, 2024
CVE-2024-0051
7.8 HIGH

In onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-0050
7.8 HIGH

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could lead to a local non-security …

Mar 11, 2024
CVE-2024-0049
7.8 HIGH

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege …

Mar 11, 2024
CVE-2024-0048
7.8 HIGH

In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to …

Mar 11, 2024
CVE-2024-0047
5.5 MEDIUM

In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local …

Mar 11, 2024
CVE-2024-0046
7.8 HIGH

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation …

Mar 11, 2024
CVE-2024-0045
6.5 MEDIUM

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure …

Mar 11, 2024
CVE-2024-0044
6.7 MEDIUM

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with …

Mar 11, 2024
CVE-2024-0039
9.8 CRITICAL

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Mar 11, 2024
CVE-2024-23612
7.8 HIGH

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially …

Mar 11, 2024
CVE-2024-23611
7.8 HIGH

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Mar 11, 2024
CVE-2024-23610
7.8 HIGH

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Mar 11, 2024
CVE-2024-23609
7.8 HIGH

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially …

Mar 11, 2024
CVE-2024-23608
7.8 HIGH

An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to …

Mar 11, 2024
CVE-2024-0670
8.8 HIGH

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Mar 11, 2024
CVE-2024-1441
5.5 MEDIUM

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This …

Mar 11, 2024
CVE-2024-2370

Rejected reason: DO NOT USE THIS CVE ID NUMBER. Consult IDs: CVE-2018-5341. Reason: This CVE Record is a duplicate of CVE-2018-5341. Notes: All CVE users …

Mar 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.