CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40516
8.8 HIGH

An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing functionality.

Jul 16, 2024
CVE-2024-33181
8.8 HIGH

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.

Jul 16, 2024
CVE-2024-6089
7.5 HIGH

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result …

Jul 16, 2024
CVE-2024-40626
7.3 HIGH

Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting …

Jul 16, 2024
CVE-2024-3232
7.6 HIGH

A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to …

Jul 16, 2024
CVE-2019-16641
8.4 HIGH

An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login …

Jul 16, 2024
CVE-2019-16640
7.5 HIGH

An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html are …

Jul 16, 2024
CVE-2019-16638
7.5 HIGH

An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects …

Jul 16, 2024
CVE-2024-40322
8.8 HIGH

An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data

Jul 16, 2024
CVE-2024-6655
7.0 HIGH

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from …

Jul 16, 2024
CVE-2024-32861
7.8 HIGH

Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.

Jul 16, 2024
CVE-2024-6435
8.8 HIGH

A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be …

Jul 16, 2024
CVE-2022-48866
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. …

Jul 16, 2024
CVE-2022-48858
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix a race on command flush flow Fix a refcount use after free warning …

Jul 16, 2024
CVE-2022-48855
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: fix kernel-infoleak for SCTP sockets syzbot reported a kernel infoleak [1] of 4 bytes. …

Jul 16, 2024
CVE-2022-48854
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: arc_emac: Fix use after free in arc_mdio_probe() If bus->state is equal to MDIOBUS_ALLOCATED, mdiobus_free(bus) …

Jul 16, 2024
CVE-2022-48851
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: staging: gdm724x: fix use after free in gdm_lte_rx() The netif_rx_ni() function frees the skb so …

Jul 16, 2024
CVE-2022-48848
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Do not unregister events twice Nicolas reported that using: # trace-cmd record -e all …

Jul 16, 2024
CVE-2022-48847
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: watch_queue: Fix filter limit check In watch_queue_set_filter(), there are a couple of places where we …

Jul 16, 2024
CVE-2022-48837
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset" is very large the "BufOffset …

Jul 16, 2024
CVE-2022-48834
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: Fix bug in pipe direction for control transfers The syzbot fuzzer reported a …

Jul 16, 2024
CVE-2022-48827
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix the behavior of READ near OFFSET_MAX Dan Aloni reports: > Due to commit …

Jul 16, 2024
CVE-2022-48822
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: f_fs: Fix use-after-free for epfile Consider a case where ffs_func_eps_disable is called from ffs_func_disable …

Jul 16, 2024
CVE-2022-48821
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: avoid double fput() on failed usercopy If the copy back to userland fails …

Jul 16, 2024
CVE-2022-48820
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: phy: stm32: fix a refcount leak in stm32_usbphyc_pll_enable() This error path needs to decrement "usbphyc->n_pll_cons.counter" …

Jul 16, 2024
CVE-2022-48805
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup ax88179_rx_fixup() contains several out-of-bounds accesses that …

Jul 16, 2024
CVE-2022-48801
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix file related error handling in IIO_BUFFER_GET_FD_IOCTL If we fail to copy the …

Jul 16, 2024
CVE-2022-48796
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu: Fix potential use-after-free during probe Kasan has reported the following use after free on …

Jul 16, 2024
CVE-2022-48792
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free may occur if a …

Jul 16, 2024
CVE-2022-48791
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted TMF sas_task Currently a use-after-free may occur if a …

Jul 16, 2024
CVE-2022-48790
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvme: fix a possible use-after-free in controller reset during load Unlike .queue_rq, in .submit_async_event drivers …

Jul 16, 2024
CVE-2022-48789
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix possible use-after-free in transport error_recovery work While nvme_tcp_submit_async_event_work is checking the ctrl and …

Jul 16, 2024
CVE-2022-48788
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix possible use-after-free in transport error_recovery work While nvme_rdma_submit_async_event_work is checking the ctrl and …

Jul 16, 2024
CVE-2022-48787
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iwlwifi: fix use-after-free If no firmware was present at all (or, presumably, all of the …

Jul 16, 2024
CVE-2022-48783
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: fix use after free in gswip_remove() of_node_put(priv->ds->slave_mii_bus->dev.of_node) should be done before mdiobus_free(priv->ds->slave_mii_bus).

Jul 16, 2024
CVE-2022-48782
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mctp: fix use after free Clang static analysis reports this problem route.c:425:4: warning: Use of …

Jul 16, 2024
CVE-2022-48779
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix use-after-free in ocelot_vlan_del() ocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so if …

Jul 16, 2024
CVE-2022-48778
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: gpmi: don't leak PM reference in error path If gpmi_nfc_apply_timings() fails, the PM …

Jul 16, 2024
CVE-2021-47624
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount leak issues take place in an …

Jul 16, 2024
CVE-2024-1937
7.1 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function …

Jul 16, 2024
CVE-2023-52290
8.1 HIGH

In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and …

Jul 16, 2024
CVE-2024-40631
8.1 HIGH

Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable …

Jul 15, 2024
CVE-2024-36438
7.3 HIGH

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other …

Jul 15, 2024
CVE-2024-36434
7.5 HIGH

An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-36433
7.5 HIGH

An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-36432
7.5 HIGH

An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-27240
7.1 HIGH

Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.

Jul 15, 2024
CVE-2024-27238
7.1 HIGH

Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege …

Jul 15, 2024
CVE-2024-40560
7.3 HIGH

Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.

Jul 15, 2024
CVE-2024-40554
7.5 HIGH

An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.

Jul 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.