CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27235
5.5 MEDIUM

In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-27234
5.9 MEDIUM

In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-27230
5.1 MEDIUM

In ProtocolPsKeepAliveStatusAdapter::getCode() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-27225
4.4 MEDIUM

In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-27223
5.1 MEDIUM

In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Mar 11, 2024
CVE-2024-27218
5.5 MEDIUM

In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-25990
6.4 MEDIUM

In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege …

Mar 11, 2024
CVE-2024-25989
5.9 MEDIUM

In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-25987
6.7 MEDIUM

In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Mar 11, 2024
CVE-2024-25984
6.2 MEDIUM

In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-22010
5.5 MEDIUM

In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-22007
6.2 MEDIUM

In constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Mar 11, 2024
CVE-2024-22006
5.3 MEDIUM

OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.

Mar 11, 2024
CVE-2024-26618
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64/sme: Always exit sme_alloc() early with existing storage When sme_alloc() is called with existing storage …

Mar 11, 2024
CVE-2024-26615
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix illegal rmb_desc access in SMC-D connection dump A crash was found when dumping …

Mar 11, 2024
CVE-2024-26614
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program …

Mar 11, 2024
CVE-2024-26612
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs, fscache: Prevent Oops in fscache_put_cache() This function dereferences "cache" and then checks if it's …

Mar 11, 2024
CVE-2024-26611
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of multi-buffer BPF helpers for ZC XDP Currently when packet is shrunk …

Mar 11, 2024
CVE-2024-1487
5.4 MEDIUM

The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as …

Mar 11, 2024
CVE-2024-1290
6.5 MEDIUM

The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, …

Mar 11, 2024
CVE-2024-1279
4.3 MEDIUM

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

Mar 11, 2024
CVE-2024-1273
6.1 MEDIUM

The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to …

Mar 11, 2024
CVE-2024-0561
5.4 MEDIUM

The Ultimate Posts Widget WordPress plugin before 2.3.1 does not validate and escape some of its Widget options before outputting them back in attributes, which …

Mar 11, 2024
CVE-2024-0559
6.5 MEDIUM

The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which …

Mar 11, 2024
CVE-2023-7247
4.9 MEDIUM

The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.

Mar 11, 2024
CVE-2023-6444
5.3 MEDIUM

The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated …

Mar 11, 2024
CVE-2023-52498
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PM: sleep: Fix possible deadlocks in core system-wide PM code It is reported that in …

Mar 11, 2024
CVE-2023-52493
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Drop chan lock before queuing buffers Ensure read and write locks for …

Mar 11, 2024
CVE-2023-52492
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fix NULL pointer in channel unregistration function __dma_async_device_channel_register() can fail. In case of failure, …

Mar 11, 2024
CVE-2023-52490
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: migrate: fix getting incorrect page mapping during page migration When running stress-ng testing, we …

Mar 11, 2024
CVE-2023-52489
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/sparsemem: fix race in accessing memory_section->usage The below race is observed on a PFN which …

Mar 11, 2024
CVE-2023-52488
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: convert from _raw_ to _noinc_ regmap functions for FIFO The SC16IS7XX IC supports …

Mar 11, 2024
CVE-2023-52487
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix peer flow lists handling The cited change refactored mlx5e_tc_del_fdb_peer_flow() to only clear DUP …

Mar 11, 2024
CVE-2023-52486
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm: Don't unref the same fb many times by mistake due to deadlock handling If …

Mar 11, 2024
CVE-2024-0047
5.5 MEDIUM

In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local …

Mar 11, 2024
CVE-2024-0045
6.5 MEDIUM

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure …

Mar 11, 2024
CVE-2024-0044
6.7 MEDIUM

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with …

Mar 11, 2024
CVE-2024-1441
5.5 MEDIUM

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This …

Mar 11, 2024
CVE-2024-28823
6.1 MEDIUM

Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html.

Mar 11, 2024
CVE-2024-2363
5.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. This vulnerability affects unknown code …

Mar 10, 2024
CVE-2024-2354
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of …

Mar 10, 2024
CVE-2024-2352
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the …

Mar 10, 2024
CVE-2024-2351
6.3 MEDIUM

A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of …

Mar 9, 2024
CVE-2024-2333
6.3 MEDIUM

A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation …

Mar 9, 2024
CVE-2024-2332
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Mar 9, 2024
CVE-2024-2331
6.3 MEDIUM

A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file …

Mar 9, 2024
CVE-2024-1870
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in …

Mar 9, 2024
CVE-2024-2330
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file …

Mar 9, 2024
CVE-2024-2329
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 9, 2024
CVE-2024-28089
5.2 MEDIUM

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panel) to conduct a DOM-based stored …

Mar 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.