CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49969
4.3 MEDIUM

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

Mar 5, 2024
CVE-2023-49968
7.3 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.

Mar 5, 2024
CVE-2023-49548
8.8 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

Mar 5, 2024
CVE-2023-49547
9.8 CRITICAL

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

Mar 5, 2024
CVE-2023-49546
8.8 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.

Mar 5, 2024
CVE-2024-1936
7.5 HIGH

The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when …

Mar 4, 2024
CVE-2023-41829
5.0 MEDIUM

An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

Mar 4, 2024
CVE-2023-41827
5.1 MEDIUM

An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on …

Mar 4, 2024
CVE-2024-2168
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of …

Mar 4, 2024
CVE-2024-1319
4.3 MEDIUM

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any …

Mar 4, 2024
CVE-2024-1316
6.5 MEDIUM

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor …

Mar 4, 2024
CVE-2024-2048
8.1 HIGH

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In …

Mar 4, 2024
CVE-2024-27889
8.8 HIGH

Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report …

Mar 4, 2024
CVE-2023-6068
3.1 LOW

On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the …

Mar 4, 2024
CVE-2023-32331
7.5 HIGH

IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its …

Mar 4, 2024
CVE-2021-47108
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf In commit 41ca9caaae0b ("drm/mediatek: hdmi: Add check …

Mar 4, 2024
CVE-2021-47107
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is …

Mar 4, 2024
CVE-2021-47106
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nft_set_catchall_destroy() We need to use list_for_each_entry_safe() iterator because we can …

Mar 4, 2024
CVE-2021-47105
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: xsk: return xsk buffers back to pool when cleaning the ring Currently we only …

Mar 4, 2024
CVE-2021-47104
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/qib: Fix memory leak in qib_user_sdma_queue_pkts() The wrong goto label was used for the error …

Mar 4, 2024
CVE-2024-27199
7.3 HIGH KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Mar 4, 2024
CVE-2024-27198
9.8 CRITICAL KEV

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Mar 4, 2024
CVE-2023-38360
6.1 MEDIUM

IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 4, 2024
CVE-2021-47103
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one …

Mar 4, 2024
CVE-2021-47102
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix incorrect structure access In line: upper = info->upper_dev; We access upper_dev …

Mar 4, 2024
CVE-2021-47101
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this …

Mar 4, 2024
CVE-2021-47100
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix UAF when uninstall ipmi_si and ipmi_msghandler module Hi, When testing install and uninstall …

Mar 4, 2024
CVE-2021-47099
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: veth: ensure skb entering GRO are not cloned. After commit d3256efd8e8b ("veth: allow enabling NAPI …

Mar 4, 2024
CVE-2021-47098
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations Commit b50aa49638c7 ("hwmon: (lm90) Prevent integer underflows …

Mar 4, 2024
CVE-2021-47097
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: elantech - fix stack out of bound access in elantech_change_report_id() The array param[] in …

Mar 4, 2024
CVE-2021-47096
4.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space …

Mar 4, 2024
CVE-2021-47095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi: ssif: initialize ssif_info->client early During probe ssif_info->client is dereferenced in error path. However, it …

Mar 4, 2024
CVE-2021-47094
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Don't advance iterator after restart due to yielding After dropping mmu_lock in the …

Mar 4, 2024
CVE-2021-47093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel_pmc_core: fix memleak on registration failure In case device registration fails during module initialisation, …

Mar 4, 2024
CVE-2021-47092
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Always clear vmx->fail on emulation_required Revert a relatively recent change that set vmx->fail …

Mar 4, 2024
CVE-2021-47091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix locking in ieee80211_start_ap error path We need to hold the local->mtx to release …

Mar 4, 2024
CVE-2021-47090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() Hulk Robot reported a panic in put_page_testzero() when testing …

Mar 4, 2024
CVE-2021-47089
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: kfence: fix memory leak when cat kfence objects Hulk robot reported a kmemleak problem: unreferenced …

Mar 4, 2024
CVE-2021-47088
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: protect targets destructions with kdamond_lock DAMON debugfs interface iterates current monitoring targets in 'dbgfs_target_ids_read()' …

Mar 4, 2024
CVE-2021-47087
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) …

Mar 4, 2024
CVE-2021-47086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phonet/pep: refuse to enable an unbound pipe This ioctl() implicitly assumed that the socket was …

Mar 4, 2024
CVE-2021-47085

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 4, 2024
CVE-2021-47084

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 4, 2024
CVE-2021-47083
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: fix global-out-of-bounds issue When eint virtual eint number is greater than gpio number, …

Mar 4, 2024
CVE-2021-47082
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tun: avoid double free in tun_free_netdev Avoid double free in tun_free_netdev() by moving the dev->tstats …

Mar 4, 2024
CVE-2024-27694
7.4 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.

Mar 4, 2024
CVE-2023-5451
6.1 MEDIUM

Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of …

Mar 4, 2024
CVE-2023-38362
5.3 MEDIUM

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.

Mar 4, 2024
CVE-2022-43890
5.3 MEDIUM

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. …

Mar 4, 2024
CVE-2024-27680
6.1 MEDIUM

Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."

Mar 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.