CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46973
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Avoid potential use after free in MHI send It is possible that the …

Feb 27, 2024
CVE-2021-46972
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ovl: fix leaked dentry Since commit 6815f479ca90 ("ovl: use only uppermetacopy state in ovl_lookup()"), overlayfs …

Feb 27, 2024
CVE-2021-46971
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix unconditional security_locked_down() call Currently, the lockdown state is queried unconditionally, even though its …

Feb 27, 2024
CVE-2021-46970
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: pci_generic: Remove WQ_MEM_RECLAIM flag from state workqueue A recent change created a dedicated …

Feb 27, 2024
CVE-2021-46969
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Fix invalid error returning in mhi_queue mhi_queue returns an error when the …

Feb 27, 2024
CVE-2021-46968
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: fix zcard and zqueue hot-unplug memleak Tests with kvm and a kmemdebug kernel showed, …

Feb 27, 2024
CVE-2021-46967
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix vm_flags for virtqueue doorbell mapping The virtqueue doorbell is usually implemented via registeres …

Feb 27, 2024
CVE-2021-46966
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ACPI: custom_method: fix potential use-after-free issue In cm_write(), buf is always freed when reaching the …

Feb 27, 2024
CVE-2021-46965
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: physmap: physmap-bt1-rom: Fix unintentional stack access Cast &data to (char *) in order to …

Feb 27, 2024
CVE-2021-46964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reserve extra IRQ vectors Commit a6dcfe08487e ("scsi: qla2xxx: Limit interrupt vectors to number …

Feb 27, 2024
CVE-2021-46963
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand() RIP: 0010:kmem_cache_free+0xfa/0x1b0 Call Trace: qla2xxx_mqueuecommand+0x2b5/0x2c0 [qla2xxx] scsi_queue_rq+0x5e2/0xa40 __blk_mq_try_issue_directly+0x128/0x1d0 blk_mq_request_issue_directly+0x4e/0xb0 …

Feb 27, 2024
CVE-2021-46962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: uniphier-sd: Fix a resource leak in the remove function A 'tmio_mmc_host_free()' call is missing …

Feb 27, 2024
CVE-2021-46961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3: Do not enable irqs when handling spurious interrups We triggered the following error while …

Feb 27, 2024
CVE-2021-46960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Return correct error code from smb2_get_enc_key Avoid a warning if the error percolates back …

Feb 27, 2024
CVE-2021-46958
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race between transaction aborts and fsyncs leading to use-after-free There is a race …

Feb 27, 2024
CVE-2021-46957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv/kprobe: fix kernel panic when invoking sys_read traced by kprobe The execution of sys_read end …

Feb 27, 2024
CVE-2021-46956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the same tag to qemu, …

Feb 27, 2024
CVE-2021-46955
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with …

Feb 27, 2024
CVE-2021-46954
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_frag: fix stack OOB read while fragmenting IPv4 packets when 'act_mirred' tries to fragment …

Feb 27, 2024
CVE-2021-46953
6.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: GTDT: Don't corrupt interrupt mappings on watchdow probe failure When failing the driver probe …

Feb 27, 2024
CVE-2021-46952
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFS: fs_context: validate UDP retrans to prevent shift out-of-bounds Fix shift out-of-bounds in xprt_calc_majortimeo(). This …

Feb 27, 2024
CVE-2021-46951
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: efi: Use local variable for calculating final log size When tpm_read_log_efi is called multiple …

Feb 27, 2024
CVE-2021-46950
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: md/raid1: properly indicate failure when ending a failed write request This patch addresses a data …

Feb 27, 2024
CVE-2021-46949
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX flush done handling We're starting from a …

Feb 27, 2024
CVE-2021-46948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX event handling We're starting from a TXQ …

Feb 27, 2024
CVE-2021-46947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: adjust efx->xdp_tx_queue_count with the real number of initialized queues efx->xdp_tx_queue_count is initially initialized to …

Feb 27, 2024
CVE-2021-46946

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 27, 2024
CVE-2021-46945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: always panic when errors=panic is specified Before commit 014c9caa29d3 ("ext4: make ext4_abort() use __ext4_error()"), …

Feb 27, 2024
CVE-2021-46944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: staging/intel-ipu3: Fix memory leak in imu_fmt We are losing the reference to an allocated …

Feb 27, 2024
CVE-2021-46943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: staging/intel-ipu3: Fix set_fmt error handling If there in an error during a set_fmt, do …

Feb 27, 2024
CVE-2021-46942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix shared sqpoll cancellation hangs [ 736.982891] INFO: task iou-sqp-4294:4295 blocked for more than …

Feb 27, 2024
CVE-2021-46941
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: Do core softreset when switch mode According to the programming guide, to …

Feb 27, 2024
CVE-2021-46940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix offset overflow issue in index converting The idx_to_offset() function returns type int …

Feb 27, 2024
CVE-2021-46939
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Restructure trace_clock_global() to never block It was reported that a fix to the ring …

Feb 27, 2024
CVE-2021-46938
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails When …

Feb 27, 2024
CVE-2020-36777
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_free() dvb_media_device_free() is leaking memory. Free `dvbdev->adapter->conn` before setting …

Feb 27, 2024
CVE-2020-36776
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue Slab OOB issue is scanned by KASAN in cpu_power_to_freq(). If …

Feb 27, 2024
CVE-2024-25846
9.1 CRITICAL

In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.

Feb 27, 2024
CVE-2024-25843
9.8 CRITICAL

In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform …

Feb 27, 2024
CVE-2024-25841
5.9 MEDIUM

In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.

Feb 27, 2024
CVE-2024-25840
7.5 HIGH

In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download …

Feb 27, 2024
CVE-2024-24323
7.2 HIGH

SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java …

Feb 27, 2024
CVE-2024-21742
5.3 MEDIUM

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to …

Feb 27, 2024
CVE-2024-1926
6.3 MEDIUM

A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown …

Feb 27, 2024
CVE-2024-1925
5.0 MEDIUM

A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipulation leads …

Feb 27, 2024
CVE-2024-1924
6.3 MEDIUM

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /get_membership_amount.php. …

Feb 27, 2024
CVE-2023-50380
6.5 MEDIUM

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie …

Feb 27, 2024
CVE-2023-48682
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Feb 27, 2024
CVE-2023-48681
6.1 MEDIUM

Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Feb 27, 2024
CVE-2023-48680
5.5 MEDIUM

Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.

Feb 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.