CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24859
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial …

Feb 5, 2024
CVE-2024-24858
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading …

Feb 5, 2024
CVE-2024-24857
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to …

Feb 5, 2024
CVE-2024-24855
5.0 MEDIUM

A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-23196
5.3 MEDIUM

A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-22667
7.8 HIGH

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to …

Feb 5, 2024
CVE-2024-22386
5.3 MEDIUM

A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-24865
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: …

Feb 5, 2024
CVE-2024-24848
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MJS Software PT Sign Ups – Beautiful volunteer sign ups and management made …

Feb 5, 2024
CVE-2024-24847
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois CalculatorPro Calculators allows Reflected XSS.This issue affects CalculatorPro Calculators: from n/a through …

Feb 5, 2024
CVE-2024-24846
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Addons for Elementor allows Reflected XSS.This issue affects Mighty Addons for …

Feb 5, 2024
CVE-2024-24841
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Customer for WooCommerce allows Stored XSS.This issue affects Add Customer …

Feb 5, 2024
CVE-2024-24839
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects …

Feb 5, 2024
CVE-2024-24838
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five …

Feb 5, 2024
CVE-2023-7077
9.8 CRITICAL

Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, …

Feb 5, 2024
CVE-2024-24870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a …

Feb 5, 2024
CVE-2024-24866
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Reflected XSS.This issue …

Feb 5, 2024
CVE-2024-20016
4.4 MEDIUM

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System …

Feb 5, 2024
CVE-2024-20015
7.8 HIGH

In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional …

Feb 5, 2024
CVE-2024-20013
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20012
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20011
9.8 CRITICAL

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional …

Feb 5, 2024
CVE-2024-20010
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20009
8.8 HIGH

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege …

Feb 5, 2024
CVE-2024-20007
7.5 HIGH

In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with …

Feb 5, 2024
CVE-2024-20006
6.7 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20004
7.5 HIGH

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW …

Feb 5, 2024
CVE-2024-20003
7.5 HIGH

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW …

Feb 5, 2024
CVE-2024-20002
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20001
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2023-5800
5.4 MEDIUM

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for …

Feb 5, 2024
CVE-2023-5677
6.3 MEDIUM

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation …

Feb 5, 2024
CVE-2023-51504
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's …

Feb 5, 2024
CVE-2023-47170

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2023.

Feb 5, 2024
CVE-2024-25089
9.8 CRITICAL

Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.

Feb 4, 2024
CVE-2021-46903
6.5 MEDIUM

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in …

Feb 4, 2024
CVE-2021-46902
7.2 HIGH

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin …

Feb 4, 2024
CVE-2023-52426
5.5 MEDIUM

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

Feb 4, 2024
CVE-2023-52425
7.5 HIGH

libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which …

Feb 4, 2024
CVE-2021-4435
7.7 HIGH

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could …

Feb 4, 2024
CVE-2020-36773
9.8 CRITICAL

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map …

Feb 4, 2024
CVE-2018-25098
4.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in blockmason credit-protocol. It has been declared as problematic. Affected by this vulnerability is the function …

Feb 4, 2024
CVE-2024-25062
7.5 HIGH

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, …

Feb 4, 2024
CVE-2023-6240
6.5 MEDIUM

A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt …

Feb 4, 2024
CVE-2019-25159
5.5 MEDIUM

A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This affects an unknown part of the …

Feb 4, 2024
CVE-2015-10129
3.7 LOW

A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/inc/auth.inc.php. …

Feb 4, 2024
CVE-2023-50947
5.4 MEDIUM

IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Feb 4, 2024
CVE-2023-33851
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could reveal sensitive partition data to a system administrator. IBM X-Force ID: …

Feb 4, 2024
CVE-2024-1215
3.5 LOW

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Feb 3, 2024
CVE-2024-0853
5.3 MEDIUM

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to …

Feb 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.