CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50198
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6030: fix IIO device retrieval from embedded device The dev pointer that is …

Nov 8, 2024
CVE-2024-50197
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: intel: platform: fix error path in device_for_each_child_node() The device_for_each_child_node() loop requires calls to fwnode_handle_put() …

Nov 8, 2024
CVE-2024-50196
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: ocelot: fix system hang on level based interrupts The current implementation only calls chained_irq_enter() …

Nov 8, 2024
CVE-2024-50195
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: posix-clock: Fix missing timespec64 check in pc_clock_settime() As Andrew pointed out, it will make sense …

Nov 8, 2024
CVE-2024-50194
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: probes: Fix uprobes for big-endian kernels The arm64 uprobes code is broken for big-endian …

Nov 8, 2024
CVE-2024-50192
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE Kunkun Jiang reported that there is …

Nov 8, 2024
CVE-2024-50191
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: don't set SB_RDONLY after filesystem errors When the filesystem is mounted with errors=remount-ro, we …

Nov 8, 2024
CVE-2024-50190
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: fix memleak in ice_init_tx_topology() Fix leak of the FW blob (DDP pkg). Make ice_cfg_tx_topo() …

Nov 8, 2024
CVE-2024-50189
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: amd_sfh: Switch to device-managed dmam_alloc_coherent() Using the device-managed version allows to simplify clean-up in …

Nov 8, 2024
CVE-2024-50188
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: dp83869: fix memory corruption when enabling fiber When configuring the fiber port, the …

Nov 8, 2024
CVE-2024-50187
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Stop the active perfmon before being destroyed Upon closing the file descriptor, the active …

Nov 8, 2024
CVE-2024-50185
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting …

Nov 8, 2024
CVE-2024-50184
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio_pmem: Check device status before requesting flush If a pmem device is in a bad …

Nov 8, 2024
CVE-2024-50183
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance Deleting an NPIV instance …

Nov 8, 2024
CVE-2024-50182
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: secretmem: disable memfd_secret() if arch cannot set direct map Return -ENOSYS from memfd_secret() syscall if …

Nov 8, 2024
CVE-2024-50179
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: remove the incorrect Fw reference check when dirtying pages When doing the direct-io reads …

Nov 8, 2024
CVE-2024-50178
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cpufreq: loongson3: Use raw_smp_processor_id() in do_service_request() Use raw_smp_processor_id() instead of plain smp_processor_id() in do_service_request(), otherwise …

Nov 8, 2024
CVE-2024-50177
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a UBSAN warning in DML2.1 When programming phantom pipe, since cursor_width is explicity …

Nov 8, 2024
CVE-2024-50176
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: remoteproc: k3-r5: Fix error handling when power-up failed By simply bailing out, the driver was …

Nov 8, 2024
CVE-2024-50175
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: qcom: camss: Remove use_count guard in stop_streaming The use_count check was introduced so that …

Nov 8, 2024
CVE-2024-50174
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix race when converting group handle to group object XArray provides it's own internal …

Nov 8, 2024
CVE-2024-50173
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup() The group variable can't be used to …

Nov 8, 2024
CVE-2024-10994
6.3 MEDIUM

A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Nov 8, 2024
CVE-2024-10993
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of the file /manage_website.php. …

Nov 8, 2024
CVE-2024-10621
6.4 MEDIUM

The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, …

Nov 8, 2024
CVE-2024-10990
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0. This vulnerability affects unknown code of the file /admin/services/view_service.php. The manipulation …

Nov 8, 2024
CVE-2024-10989
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects E-Health Care System 1.0. This affects an unknown part of the file /Admin/detail.php. The manipulation …

Nov 8, 2024
CVE-2024-10987
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Nov 8, 2024
CVE-2024-48010
6.5 MEDIUM

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this …

Nov 8, 2024
CVE-2024-45759
6.8 MEDIUM

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially …

Nov 8, 2024
CVE-2024-51987
5.4 MEDIUM

Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's …

Nov 8, 2024
CVE-2024-8810
6.5 MEDIUM

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require …

Nov 7, 2024
CVE-2024-51434
6.1 MEDIUM

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

Nov 7, 2024
CVE-2024-49524
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute …

Nov 7, 2024
CVE-2024-49523
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Nov 7, 2024
CVE-2024-36064
6.2 MEDIUM

The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction …

Nov 7, 2024
CVE-2024-36062
4.0 MEDIUM

The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user …

Nov 7, 2024
CVE-2024-10824
6.5 MEDIUM

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for …

Nov 7, 2024
CVE-2024-50599
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from …

Nov 7, 2024
CVE-2019-20472
6.2 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, …

Nov 7, 2024
CVE-2019-20469
4.6 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the …

Nov 7, 2024
CVE-2019-20462
5.3 MEDIUM

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial …

Nov 7, 2024
CVE-2024-51994
5.4 MEDIUM

Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will …

Nov 7, 2024
CVE-2024-48290
4.3 MEDIUM

An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Nov 7, 2024
CVE-2024-10966
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file …

Nov 7, 2024
CVE-2020-11918
5.4 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can …

Nov 7, 2024
CVE-2020-11917
4.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical …

Nov 7, 2024
CVE-2020-11916
6.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of …

Nov 7, 2024
CVE-2024-48954
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

Nov 7, 2024
CVE-2024-48952
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints …

Nov 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.