CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51512
4.3 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in WBW Product Table by WBW.This issue affects Product Table by WBW: from n/a through 1.8.6.

Mar 16, 2024
CVE-2023-51510
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Atlas Gondal Export Media URLs.This issue affects Export Media URLs: from n/a through 1.0.

Mar 16, 2024
CVE-2023-51491
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Averta Depicter Slider.This issue affects Depicter Slider: from n/a through 2.0.6.

Mar 16, 2024
CVE-2023-51489
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from …

Mar 16, 2024
CVE-2023-51407
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.

Mar 16, 2024
CVE-2024-28862
5.3 MEDIUM

The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default …

Mar 16, 2024
CVE-2024-28859
5.0 MEDIUM

Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 support. Symfony 1 has …

Mar 15, 2024
CVE-2024-23298
5.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

Mar 15, 2024
CVE-2021-47134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid …

Mar 15, 2024
CVE-2021-47133
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: amd_sfh: Fix memory leak in amd_sfh_work Kmemleak tool detected a memory leak in the …

Mar 15, 2024
CVE-2021-47130
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool …

Mar 15, 2024
CVE-2021-47129
4.6 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: skip expectations for confirmed conntrack nft_ct_expect_obj_eval() calls nf_ct_ext_add() for a confirmed conntrack entry. …

Mar 15, 2024
CVE-2021-47128
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf, lockdown, audit: Fix buggy SELinux lockdown permission checks Commit 59438b46471a ("security,lockdown,selinux: implement SELinux lockdown") …

Mar 15, 2024
CVE-2021-47127
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: track AF_XDP ZC enabled queues in bitmap Commit c7a219048e45 ("ice: Remove xsk_buff_pool from VSI …

Mar 15, 2024
CVE-2021-47126
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions Reported by syzbot: HEAD commit: 90c911ad Merge tag …

Mar 15, 2024
CVE-2021-47125
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sch_htb: fix refcount leak in htb_parent_to_leaf_offload The commit ae81feb7338c ("sch_htb: fix null pointer dereference on …

Mar 15, 2024
CVE-2021-47124
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix link timeout refs WARNING: CPU: 0 PID: 10242 at lib/refcount.c:28 refcount_warn_saturate+0x15b/0x1a0 lib/refcount.c:28 RIP: …

Mar 15, 2024
CVE-2021-47122
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in caif_device_notify In case of caif_enroll_dev() fail, allocated link_support won't …

Mar 15, 2024
CVE-2021-47121
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail, allocated link_support won't …

Mar 15, 2024
CVE-2021-47120
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: fix NULL-deref on disconnect Commit 9d7b18668956 ("HID: magicmouse: add support for Apple Magic …

Mar 15, 2024
CVE-2021-47119
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_fill_super Buffer head references must be released before calling kill_bdev(); …

Mar 15, 2024
CVE-2021-47117
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug on in ext4_es_cache_extent as ext4_split_extent_at failed We got follow bug_on when run …

Mar 15, 2024
CVE-2021-47116
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leak in ext4_mb_init_backend on error path. Fix a memory leak discovered by …

Mar 15, 2024
CVE-2021-47114
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption by fallocate When fallocate punches holes out of inode size, if …

Mar 15, 2024
CVE-2021-47113
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: abort in rename_exchange if we fail to insert the second ref Error injection stress …

Mar 15, 2024
CVE-2021-47112
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/kvm: Teardown PV features on boot CPU as well Various PV features (Async PF, PV …

Mar 15, 2024
CVE-2021-47109
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. …

Mar 15, 2024
CVE-2024-28242
5.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. …

Mar 15, 2024
CVE-2024-27351
5.3 MEDIUM

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to …

Mar 15, 2024
CVE-2024-27100
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing …

Mar 15, 2024
CVE-2024-27085
6.5 MEDIUM

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in …

Mar 15, 2024
CVE-2024-24827
5.3 MEDIUM

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker …

Mar 15, 2024
CVE-2024-24748
5.3 MEDIUM

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category …

Mar 15, 2024
CVE-2023-7248
5.0 MEDIUM

Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by …

Mar 15, 2024
CVE-2024-28851
4.0 MEDIUM

The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of …

Mar 15, 2024
CVE-2023-51699
4.0 MEDIUM

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can …

Mar 15, 2024
CVE-2024-2537
4.4 MEDIUM

Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.

Mar 15, 2024
CVE-2024-2193
5.7 MEDIUM

A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can …

Mar 15, 2024
CVE-2024-2497
4.7 MEDIUM

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component …

Mar 15, 2024
CVE-2024-28401
5.4 MEDIUM

TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.

Mar 15, 2024
CVE-2023-7004
6.5 MEDIUM

The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device …

Mar 15, 2024
CVE-2023-7003
6.8 MEDIUM

The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused …

Mar 15, 2024
CVE-2024-28403
5.4 MEDIUM

TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.

Mar 15, 2024
CVE-2023-47699
6.1 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mar 15, 2024
CVE-2023-47147
5.9 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.

Mar 15, 2024
CVE-2023-46181
4.0 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM …

Mar 15, 2024
CVE-2021-38938
6.2 MEDIUM

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by …

Mar 15, 2024
CVE-2024-28319
6.2 MEDIUM

gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374

Mar 15, 2024
CVE-2023-51522
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.10.4.

Mar 15, 2024
CVE-2023-51369
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.

Mar 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.