CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-38366
5.3 MEDIUM

IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a …

Mar 1, 2024
CVE-2023-50324
5.3 MEDIUM

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment …

Mar 1, 2024
CVE-2023-50305
5.1 MEDIUM

IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise …

Mar 1, 2024
CVE-2023-28949
6.5 MEDIUM

IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

Mar 1, 2024
CVE-2023-28525
4.8 MEDIUM

IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 1, 2024
CVE-2024-2045
5.5 MEDIUM

Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application …

Mar 1, 2024
CVE-2024-2022
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 1, 2024
CVE-2024-2021
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. Affected is an unknown function of the file …

Mar 1, 2024
CVE-2024-0403
6.5 MEDIUM

Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.

Mar 1, 2024
CVE-2021-47067
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc/tegra: regulators: Fix locking up when voltage-spread is out of range Fix voltage coupler lockup …

Feb 29, 2024
CVE-2021-47066
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: async_xor: increase src_offs when dropping destination page Now we support sharing one page if PAGE_SIZE …

Feb 29, 2024
CVE-2021-47064
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could …

Feb 29, 2024
CVE-2021-47062
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Use online_vcpus, not created_vcpus, to iterate over vCPUs Use the kvm_for_each_vcpu() helper to …

Feb 29, 2024
CVE-2021-47060
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: Stop looking for coalesced MMIO zones if the bus is destroyed Abort the walk …

Feb 29, 2024
CVE-2021-47059
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - fix result memory leak on error path This patch fixes a memory …

Feb 29, 2024
CVE-2021-47057
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to map In …

Feb 29, 2024
CVE-2021-47056
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - ADF_STATUS_PF_RUNNING should be set after adf_dev_init ADF_STATUS_PF_RUNNING is (only) used and checked …

Feb 29, 2024
CVE-2021-47055
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection …

Feb 29, 2024
CVE-2021-47054
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: qcom: Put child node before return Put child node before return to fix potential …

Feb 29, 2024
CVE-2021-47020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soundwire: stream: fix memory leak in stream config error path When stream config is failed, …

Feb 29, 2024
CVE-2021-47016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: m68k: mvme147,mvme16x: Don't wipe PCC timer config bits Don't clear the timer 1 configuration bits …

Feb 29, 2024
CVE-2024-2009
5.3 MEDIUM

A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_login_submit_form of the file …

Feb 29, 2024
CVE-2024-27662
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

Feb 29, 2024
CVE-2024-27661
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27660
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

Feb 29, 2024
CVE-2024-27659
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27658
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-24246
5.5 MEDIUM

Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.

Feb 29, 2024
CVE-2024-0068
5.5 MEDIUM

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.

Feb 29, 2024
CVE-2023-52485
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a command [Why] We can hang in place trying to …

Feb 29, 2024
CVE-2024-2001
5.5 MEDIUM

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store …

Feb 29, 2024
CVE-2024-26607
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely …

Feb 29, 2024
CVE-2024-27906
5.9 MEDIUM

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have …

Feb 29, 2024
CVE-2024-1953
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, …

Feb 29, 2024
CVE-2024-1942
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an …

Feb 29, 2024
CVE-2024-1619
6.1 MEDIUM

Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an …

Feb 29, 2024
CVE-2024-1888
4.3 MEDIUM

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members …

Feb 29, 2024
CVE-2024-24988
4.3 MEDIUM

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very …

Feb 29, 2024
CVE-2024-23493
4.3 MEDIUM

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that …

Feb 29, 2024
CVE-2024-1887
4.3 MEDIUM

Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the …

Feb 29, 2024
CVE-2024-25594
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress Development MyWaze allows Stored XSS.This issue affects MyWaze: from n/a through …

Feb 29, 2024
CVE-2024-1982
6.5 MEDIUM

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() …

Feb 29, 2024
CVE-2024-1978
5.5 MEDIUM

The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes …

Feb 29, 2024
CVE-2024-25098
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB oEmbed HTML5 Audio – with Cache Support allows Stored XSS.This …

Feb 29, 2024
CVE-2024-25094
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects …

Feb 29, 2024
CVE-2024-23501
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: from n/a …

Feb 29, 2024
CVE-2024-1977
4.4 MEDIUM

The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input …

Feb 29, 2024
CVE-2024-1976
4.3 MEDIUM

The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing …

Feb 29, 2024
CVE-2024-1434
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Media Alt Renamer allows Stored XSS.This issue affects Media Alt Renamer: …

Feb 29, 2024
CVE-2023-52484
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Fix soft lockup triggered by arm_smmu_mm_invalidate_range When running an SVA case, the following soft …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.