CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix clobbering of SWERR overflow bit on writeback Current code blindly writes over …

Feb 27, 2024
CVE-2021-46919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq size store permission state WQ size can only be changed when …

Feb 27, 2024
CVE-2021-46918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: clear MSIX permission entry on shutdown Add disabling/clearing of MSIX permission entries on …

Feb 27, 2024
CVE-2021-46917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround where wq …

Feb 27, 2024
CVE-2021-46916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: Fix NULL pointer dereference in ethtool loopback test The ixgbe driver currently generates a …

Feb 27, 2024
CVE-2021-46915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: avoid possible divide error in nft_limit_init div_u64() divides u64 by u32. nft_limit_init() wants …

Feb 27, 2024
CVE-2021-46914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix unbalanced device enable/disable in suspend/resume pci_disable_device() called in __ixgbe_shutdown() decreases dev->enable_cnt by 1. …

Feb 27, 2024
CVE-2021-46913
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: clone set element expression template memcpy() breaks when using connlimit in set elements. …

Feb 27, 2024
CVE-2021-46912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Make tcp_allowed_congestion_control readonly in non-init netns Currently, tcp_allowed_congestion_control is global and writable; writing to …

Feb 27, 2024
CVE-2021-46911
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes. …

Feb 27, 2024
CVE-2021-46910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: 9063/1: mm: reduce maximum number of CPUs if DEBUG_KMAP_LOCAL is enabled The debugging code …

Feb 27, 2024
CVE-2021-46909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: footbridge: fix PCI interrupt mapping Since commit 30fdfb929e82 ("PCI: Add a call to pci_assign_irq() …

Feb 27, 2024
CVE-2021-46908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Use correct permission flag for mixed signed bounds arithmetic We forbid adding unknown scalars …

Feb 27, 2024
CVE-2021-46907

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 27, 2024
CVE-2024-1698
9.8 CRITICAL

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via …

Feb 27, 2024
CVE-2024-1687
5.4 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to a missing …

Feb 27, 2024
CVE-2024-1686
4.3 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, …

Feb 27, 2024
CVE-2024-0759
7.5 HIGH

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, they …

Feb 27, 2024
CVE-2024-1323
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions …

Feb 27, 2024
CVE-2023-7033
5.3 MEDIUM

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface …

Feb 27, 2024
CVE-2024-25711
7.5 HIGH

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to …

Feb 27, 2024
CVE-2024-24100
8.3 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

Feb 27, 2024
CVE-2024-24099
5.4 MEDIUM

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

Feb 27, 2024
CVE-2024-24096
7.8 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.

Feb 27, 2024
CVE-2024-24095
9.8 CRITICAL

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

Feb 27, 2024
CVE-2024-22917
8.6 HIGH

SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Feb 27, 2024
CVE-2023-41506
9.8 CRITICAL

An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via …

Feb 27, 2024
CVE-2024-27356
7.5 HIGH

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 …

Feb 27, 2024
CVE-2024-25166
6.1 MEDIUM

Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfile action parameter in the controller.php file.

Feb 27, 2024
CVE-2024-24720
5.3 MEDIUM

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a …

Feb 27, 2024
CVE-2024-22544
8.0 HIGH

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.

Feb 27, 2024
CVE-2024-22543
6.1 MEDIUM

An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* …

Feb 27, 2024
CVE-2024-24721
6.5 MEDIUM

An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker …

Feb 27, 2024
CVE-2024-25247
9.8 CRITICAL

SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.

Feb 26, 2024
CVE-2024-27093
4.6 MEDIUM

Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a …

Feb 26, 2024
CVE-2024-25751
9.8 CRITICAL

A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime …

Feb 26, 2024
CVE-2024-25248
9.8 CRITICAL

SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

Feb 26, 2024
CVE-2023-36237
8.8 HIGH

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

Feb 26, 2024
CVE-2024-27089

Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not in the allowed scope of that CNA's CVE ID …

Feb 26, 2024
CVE-2024-26149
3.7 LOW

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an …

Feb 26, 2024
CVE-2024-24564
3.7 LOW

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for …

Feb 26, 2024
CVE-2024-24528

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Feb 26, 2024
CVE-2024-1899
5.3 MEDIUM

An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.

Feb 26, 2024
CVE-2024-27084

Rejected reason: This CVE is a duplicate of CVE-2024-1631.

Feb 26, 2024
CVE-2024-26455
7.5 HIGH

fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.

Feb 26, 2024
CVE-2024-25770
4.3 MEDIUM

libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.

Feb 26, 2024
CVE-2024-25768
7.5 HIGH

OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.

Feb 26, 2024
CVE-2023-52474
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests hfi1 user SDMA request processing has …

Feb 26, 2024
CVE-2021-46906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report …

Feb 26, 2024
CVE-2020-36775
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential deadlock like …

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.