CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built …

Feb 27, 2024
CVE-2021-46922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM …

Feb 27, 2024
CVE-2021-46921
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a …

Feb 27, 2024
CVE-2024-1106
6.1 MEDIUM

The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2024-0855
5.3 MEDIUM

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to …

Feb 27, 2024
CVE-2023-7203
6.1 MEDIUM

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as …

Feb 27, 2024
CVE-2023-7202
6.1 MEDIUM

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such …

Feb 27, 2024
CVE-2023-7198
4.3 MEDIUM

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete …

Feb 27, 2024
CVE-2023-7167
6.1 MEDIUM

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2023-7165
7.5 HIGH

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors …

Feb 27, 2024
CVE-2023-7115
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 27, 2024
CVE-2023-6585
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as …

Feb 27, 2024
CVE-2023-6584
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

Feb 27, 2024
CVE-2023-51518
9.8 CRITICAL

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, …

Feb 27, 2024
CVE-2023-50379
8.8 HIGH

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster …

Feb 27, 2024
CVE-2021-46920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix clobbering of SWERR overflow bit on writeback Current code blindly writes over …

Feb 27, 2024
CVE-2021-46919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq size store permission state WQ size can only be changed when …

Feb 27, 2024
CVE-2021-46918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: clear MSIX permission entry on shutdown Add disabling/clearing of MSIX permission entries on …

Feb 27, 2024
CVE-2021-46917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround where wq …

Feb 27, 2024
CVE-2021-46916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: Fix NULL pointer dereference in ethtool loopback test The ixgbe driver currently generates a …

Feb 27, 2024
CVE-2021-46915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: avoid possible divide error in nft_limit_init div_u64() divides u64 by u32. nft_limit_init() wants …

Feb 27, 2024
CVE-2021-46914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix unbalanced device enable/disable in suspend/resume pci_disable_device() called in __ixgbe_shutdown() decreases dev->enable_cnt by 1. …

Feb 27, 2024
CVE-2021-46913
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: clone set element expression template memcpy() breaks when using connlimit in set elements. …

Feb 27, 2024
CVE-2021-46912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Make tcp_allowed_congestion_control readonly in non-init netns Currently, tcp_allowed_congestion_control is global and writable; writing to …

Feb 27, 2024
CVE-2021-46911
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes. …

Feb 27, 2024
CVE-2021-46910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: 9063/1: mm: reduce maximum number of CPUs if DEBUG_KMAP_LOCAL is enabled The debugging code …

Feb 27, 2024
CVE-2021-46909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: footbridge: fix PCI interrupt mapping Since commit 30fdfb929e82 ("PCI: Add a call to pci_assign_irq() …

Feb 27, 2024
CVE-2021-46908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Use correct permission flag for mixed signed bounds arithmetic We forbid adding unknown scalars …

Feb 27, 2024
CVE-2021-46907

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 27, 2024
CVE-2024-1698
9.8 CRITICAL

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via …

Feb 27, 2024
CVE-2024-1687
5.4 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to a missing …

Feb 27, 2024
CVE-2024-1686
4.3 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, …

Feb 27, 2024
CVE-2024-0759
7.5 HIGH

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, they …

Feb 27, 2024
CVE-2024-1323
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions …

Feb 27, 2024
CVE-2023-7033
5.3 MEDIUM

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface …

Feb 27, 2024
CVE-2024-25711
7.5 HIGH

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to …

Feb 27, 2024
CVE-2024-24100
8.3 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

Feb 27, 2024
CVE-2024-24099
5.4 MEDIUM

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

Feb 27, 2024
CVE-2024-24096
7.8 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.

Feb 27, 2024
CVE-2024-24095
9.8 CRITICAL

Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

Feb 27, 2024
CVE-2024-22917
8.6 HIGH

SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Feb 27, 2024
CVE-2023-41506
9.8 CRITICAL

An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via …

Feb 27, 2024
CVE-2024-27356
7.5 HIGH

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 …

Feb 27, 2024
CVE-2024-25166
6.1 MEDIUM

Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfile action parameter in the controller.php file.

Feb 27, 2024
CVE-2024-24720
5.3 MEDIUM

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a …

Feb 27, 2024
CVE-2024-22544
8.0 HIGH

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.

Feb 27, 2024
CVE-2024-22543
6.1 MEDIUM

An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* …

Feb 27, 2024
CVE-2024-24721
6.5 MEDIUM

An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker …

Feb 27, 2024
CVE-2024-25247
9.8 CRITICAL

SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.

Feb 26, 2024
CVE-2024-27093
4.6 MEDIUM

Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a …

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.