CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35885
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mlxbf_gige: stop interface during shutdown The mlxbf_gige driver intermittantly encounters a NULL pointer exception while …

May 19, 2024
CVE-2024-35884
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel GSO skbs landing in a tunnel When rx-udp-gro-forwarding is enabled …

May 19, 2024
CVE-2024-35883
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: mchp-pci1xxx: Fix a possible null pointer dereference in pci1xxx_spi_probe In function pci1xxxx_spi_probe, there is …

May 19, 2024
CVE-2024-35882
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a slow server-side memory leak with RPC-over-TCP Jan Schunk reports that his small …

May 19, 2024
CVE-2024-35880
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: hold io_buffer_list reference over mmap If we look up the kbuf, ensure that it …

May 19, 2024
CVE-2024-35879
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: of: dynamic: Synchronize of_changeset_destroy() with the devlink removals In the following sequence: 1) of_platform_depopulate() 2) …

May 19, 2024
CVE-2024-35878
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: of: module: prevent NULL pointer dereference in vsnprintf() In of_modalias(), we can get passed the …

May 19, 2024
CVE-2024-35877
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: fix VM_PAT handling in COW mappings PAT handling won't do the right thing in …

May 19, 2024
CVE-2024-35875
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo …

May 19, 2024
CVE-2024-35874
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: aio: Fix null ptr deref in aio_complete() wakeup list_del_init_careful() needs to be the last access …

May 19, 2024
CVE-2024-35873
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix vector state restore in rt_sigreturn() The RISC-V Vector specification states in "Appendix D: …

May 19, 2024
CVE-2024-35872
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix GUP-fast succeeding on secretmem folios folio_is_secretmem() currently relies on secretmem folios being LRU …

May 19, 2024
CVE-2024-35870
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in smb2_reconnect_server() The UAF bug is due to smb2_reconnect_server() accessing a …

May 19, 2024
CVE-2024-35865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_oplock_break() Skip sessions that are being teared down (status …

May 19, 2024
CVE-2024-35860
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: support deferring bpf_link dealloc to after RCU grace period BPF link for some program …

May 19, 2024
CVE-2024-5099
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

May 19, 2024
CVE-2024-5098
5.5 MEDIUM

A vulnerability has been found in SourceCodester Simple Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

May 19, 2024
CVE-2024-5097
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Inventory System 1.0. Affected is an unknown function of the file /tableedit.php#page=editprice. The …

May 19, 2024
CVE-2024-5096
5.3 MEDIUM

A vulnerability classified as problematic was found in Hipcam Device up to 20240511. This vulnerability affects unknown code of the file /log/wifi.mac of the component …

May 19, 2024
CVE-2024-5095
6.5 MEDIUM

A vulnerability classified as problematic has been found in Victor Zsviot Camera 8.26.31. This affects an unknown part of the component MQTT Packet Handler. The …

May 19, 2024
CVE-2024-36050
4.3 MEDIUM

Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by …

May 18, 2024
CVE-2024-28063
6.1 MEDIUM

Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.

May 18, 2024
CVE-2024-36043
6.1 MEDIUM

question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.

May 18, 2024
CVE-2024-34083
5.4 MEDIUM

aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after …

May 18, 2024
CVE-2024-5088
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, …

May 18, 2024
CVE-2024-4432
6.4 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, …

May 18, 2024
CVE-2024-4709
6.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

May 18, 2024
CVE-2024-4698
6.4 MEDIUM

The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, …

May 18, 2024
CVE-2024-2772
6.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

May 18, 2024
CVE-2024-4849
6.4 MEDIUM

The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ parameter in all versions up to, and including, 3.94.0 …

May 18, 2024
CVE-2024-3811
6.4 MEDIUM

The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortcode in all versions up to, and including, 1.5.3 …

May 18, 2024
CVE-2024-4891
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in …

May 18, 2024
CVE-2024-4374
6.4 MEDIUM

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 …

May 18, 2024
CVE-2024-3714
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with …

May 18, 2024
CVE-2024-4865
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, …

May 18, 2024
CVE-2024-23556
5.9 MEDIUM

SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.

May 18, 2024
CVE-2024-23554
5.7 MEDIUM

Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).

May 18, 2024
CVE-2024-23583
6.7 MEDIUM

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

May 17, 2024
CVE-2024-35312
6.2 MEDIUM

In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.

May 17, 2024
CVE-2024-25742
6.5 MEDIUM

In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. …

May 17, 2024
CVE-2024-5069
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management System 1.0. Affected by this issue is some …

May 17, 2024
CVE-2024-5066
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file …

May 17, 2024
CVE-2024-34959
5.5 MEDIUM

DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.

May 17, 2024
CVE-2024-5022
4.4 MEDIUM

The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for …

May 17, 2024
CVE-2024-35190
5.8 MEDIUM

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of …

May 17, 2024
CVE-2023-5597
5.4 MEDIUM

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

May 17, 2024
CVE-2024-5072
6.5 MEDIUM

Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation …

May 17, 2024
CVE-2024-34241
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating …

May 17, 2024
CVE-2024-31974
6.3 MEDIUM

The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. …

May 17, 2024
CVE-2024-5051
6.3 MEDIUM

A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. …

May 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.