CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-47078
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Clear all QP fields if creation failed rxe_qp_do_cleanup() relies on valid pointer values in …

Mar 1, 2024
CVE-2021-47077
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Add pointer checks in qedf_update_link_speed() The following trace was observed: [ 14.042059] Call …

Mar 1, 2024
CVE-2021-47076
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Return CQE error if invalid lkey was supplied RXE is missing update of WQE …

Mar 1, 2024
CVE-2021-47075
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak in nvmet_alloc_ctrl() When creating ctrl in nvmet_alloc_ctrl(), if the cntlid_min is …

Mar 1, 2024
CVE-2021-47074
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-loop: fix memory leak in nvme_loop_create_ctrl() When creating loop ctrl in nvme_loop_create_ctrl(), if nvme_init_ctrl() fails, …

Mar 1, 2024
CVE-2021-47073
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios init_dell_smbios_wmi() only registers the dell_smbios_wmi_driver on systems where …

Mar 1, 2024
CVE-2021-47072
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix removed dentries still existing after log is synced When we move one inode …

Mar 1, 2024
CVE-2021-47071
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix a memory leak in error handling paths If 'vmbus_establish_gpadl()' fails, the (recv|send)_gpadl will …

Mar 1, 2024
CVE-2021-47070
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix another memory leak in error handling paths Memory allocated by 'vmbus_alloc_ring()' at the …

Mar 1, 2024
CVE-2024-23492
5.7 MEDIUM

A weak encoding is used to transmit credentials for WS203VICM.

Mar 1, 2024
CVE-2024-20328
5.3 MEDIUM

A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The …

Mar 1, 2024
CVE-2024-2077
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file index.php. The …

Mar 1, 2024
CVE-2024-2076
5.3 MEDIUM

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Mar 1, 2024
CVE-2024-2074
6.3 MEDIUM

A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown processing of the file ?r=tmall/admin/user/1/1. The manipulation …

Mar 1, 2024
CVE-2024-2073
6.3 MEDIUM

A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Mar 1, 2024
CVE-2024-27734
6.1 MEDIUM

A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fields …

Mar 1, 2024
CVE-2024-27559
6.3 MEDIUM

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

Mar 1, 2024
CVE-2024-27558
6.1 MEDIUM

Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.

Mar 1, 2024
CVE-2023-52556
6.2 MEDIUM

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

Mar 1, 2024
CVE-2024-2069
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknown function of the file /endpoint/delete-faq.php. The manipulation …

Mar 1, 2024
CVE-2024-27499
6.5 MEDIUM

Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

Mar 1, 2024
CVE-2024-27296
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped …

Mar 1, 2024
CVE-2024-27140
5.4 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from …

Mar 1, 2024
CVE-2024-2067
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. …

Mar 1, 2024
CVE-2024-0967
4.3 MEDIUM

A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

Mar 1, 2024
CVE-2023-50378
6.1 MEDIUM

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited …

Mar 1, 2024
CVE-2024-2064
4.3 MEDIUM

A vulnerability has been found in rahman SelectCours 1.0 and classified as problematic. Affected by this vulnerability is the function getCacheNames of the file CacheController.java …

Mar 1, 2024
CVE-2024-27569
6.5 MEDIUM

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27568
6.5 MEDIUM

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27567
6.5 MEDIUM

LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause …

Mar 1, 2024
CVE-2023-52497
6.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, …

Mar 1, 2024
CVE-2023-46951
6.1 MEDIUM

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

Mar 1, 2024
CVE-2023-46950
6.1 MEDIUM

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.

Mar 1, 2024
CVE-2024-2062
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. This issue affects some unknown processing of the …

Mar 1, 2024
CVE-2024-2061
4.7 MEDIUM

A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. This vulnerability affects unknown code of the file /admin/edit_supplier.php. The manipulation …

Mar 1, 2024
CVE-2024-2060
4.7 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Petrol Pump Management Software 1.0. This affects an unknown part of the file /admin/app/login_crud.php. The …

Mar 1, 2024
CVE-2024-24900
5.8 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, …

Mar 1, 2024
CVE-2023-48674
6.8 MEDIUM

Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to …

Mar 1, 2024
CVE-2023-39254
6.7 MEDIUM

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially …

Mar 1, 2024
CVE-2024-2078
4.6 MEDIUM

A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially …

Mar 1, 2024
CVE-2024-2059
4.7 MEDIUM

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 1, 2024
CVE-2024-2057
6.3 MEDIUM

A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the …

Mar 1, 2024
CVE-2024-2058
4.7 MEDIUM

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 1, 2024
CVE-2024-26280
4.7 MEDIUM

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names …

Mar 1, 2024
CVE-2024-1120
5.3 MEDIUM

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable …

Mar 1, 2024
CVE-2024-27950
5.4 MEDIUM

Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

Mar 1, 2024
CVE-2024-27949
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

Mar 1, 2024
CVE-2023-52555
6.1 MEDIUM

In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.

Mar 1, 2024
CVE-2023-50312
5.3 MEDIUM

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user …

Mar 1, 2024
CVE-2023-47716
6.3 MEDIUM

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. …

Mar 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.