CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-47067
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc/tegra: regulators: Fix locking up when voltage-spread is out of range Fix voltage coupler lockup …

Feb 29, 2024
CVE-2021-47066
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: async_xor: increase src_offs when dropping destination page Now we support sharing one page if PAGE_SIZE …

Feb 29, 2024
CVE-2021-47065
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rtw88: Fix array overrun in rtw_get_tx_power_params() Using a kernel with the Undefined Behaviour Sanity Checker …

Feb 29, 2024
CVE-2021-47064
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could …

Feb 29, 2024
CVE-2021-47063
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm: bridge/panel: Cleanup connector on bridge detach If we don't call drm_connector_cleanup() manually in panel_bridge_detach(), …

Feb 29, 2024
CVE-2021-47062
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Use online_vcpus, not created_vcpus, to iterate over vCPUs Use the kvm_for_each_vcpu() helper to …

Feb 29, 2024
CVE-2021-47061
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a new …

Feb 29, 2024
CVE-2021-47060
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: Stop looking for coalesced MMIO zones if the bus is destroyed Abort the walk …

Feb 29, 2024
CVE-2021-47059
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - fix result memory leak on error path This patch fixes a memory …

Feb 29, 2024
CVE-2021-47058
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: regmap: set debugfs_name to NULL after it is freed There is a upstream commit cffa4b2122f5("regmap:debugfs: …

Feb 29, 2024
CVE-2021-47057
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to map In …

Feb 29, 2024
CVE-2021-47056
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - ADF_STATUS_PF_RUNNING should be set after adf_dev_init ADF_STATUS_PF_RUNNING is (only) used and checked …

Feb 29, 2024
CVE-2021-47055
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection …

Feb 29, 2024
CVE-2021-47054
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: qcom: Put child node before return Put child node before return to fix potential …

Feb 29, 2024
CVE-2021-47020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soundwire: stream: fix memory leak in stream config error path When stream config is failed, …

Feb 29, 2024
CVE-2021-47016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: m68k: mvme147,mvme16x: Don't wipe PCC timer config bits Don't clear the timer 1 configuration bits …

Feb 29, 2024
CVE-2021-46959
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: Fix use-after-free with devm_spi_alloc_* We can't rely on the contents of the devres list …

Feb 29, 2024
CVE-2024-2009
5.3 MEDIUM

A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_login_submit_form of the file …

Feb 29, 2024
CVE-2024-27662
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

Feb 29, 2024
CVE-2024-27661
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27660
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

Feb 29, 2024
CVE-2024-27659
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27658
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27657
8.8 HIGH

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Feb 29, 2024
CVE-2024-27656
8.8 HIGH

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Feb 29, 2024
CVE-2024-27655
8.8 HIGH

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Feb 29, 2024
CVE-2024-26548
9.8 CRITICAL

An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.

Feb 29, 2024
CVE-2024-24246
5.5 MEDIUM

Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.

Feb 29, 2024
CVE-2024-1595
7.8 HIGH

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where …

Feb 29, 2024
CVE-2024-0068
5.5 MEDIUM

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.

Feb 29, 2024
CVE-2024-25180
9.8 CRITICAL

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed …

Feb 29, 2024
CVE-2023-6132
7.3 HIGH

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking …

Feb 29, 2024
CVE-2024-20765
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Feb 29, 2024
CVE-2023-52485
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a command [Why] We can hang in place trying to …

Feb 29, 2024
CVE-2024-2001
5.5 MEDIUM

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store …

Feb 29, 2024
CVE-2024-0864
9.8 CRITICAL

Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a …

Feb 29, 2024
CVE-2024-26607
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely …

Feb 29, 2024
CVE-2024-27906
5.9 MEDIUM

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have …

Feb 29, 2024
CVE-2024-1953
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, …

Feb 29, 2024
CVE-2024-1952
3.1 LOW

Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can …

Feb 29, 2024
CVE-2024-1949
2.6 LOW

A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents …

Feb 29, 2024
CVE-2024-1942
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an …

Feb 29, 2024
CVE-2024-1619
6.1 MEDIUM

Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an …

Feb 29, 2024
CVE-2024-1888
4.3 MEDIUM

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members …

Feb 29, 2024
CVE-2024-24988
4.3 MEDIUM

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very …

Feb 29, 2024
CVE-2024-23493
4.3 MEDIUM

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that …

Feb 29, 2024
CVE-2024-23488
3.1 LOW

Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of …

Feb 29, 2024
CVE-2024-1887
4.3 MEDIUM

Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the …

Feb 29, 2024
CVE-2024-25594
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress Development MyWaze allows Stored XSS.This issue affects MyWaze: from n/a through …

Feb 29, 2024
CVE-2024-25292
9.6 CRITICAL

Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.