CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: mcp251xfd: mcp251xfd_probe(): fix an error pointer dereference in probe When we converted this code …

Feb 28, 2024
CVE-2021-46994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: mcp251x: fix resume from sleep before interface was brought up Since 8ce8c0abcba3 the driver …

Feb 28, 2024
CVE-2021-46990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix crashes when toggling entry flush barrier The entry flush mitigation can be enabled/disabled …

Feb 28, 2024
CVE-2021-46989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hfsplus: prevent corruption in shrinking truncate I believe there are some issues introduced by commit …

Feb 28, 2024
CVE-2021-46988
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: release page in error path to avoid BUG_ON Consider the following sequence of events: …

Feb 28, 2024
CVE-2021-46987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock when cloning inline extents and using qgroups There are a few exceptional …

Feb 28, 2024
CVE-2021-46986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Free gadget structure only after freeing endpoints As part of commit e81a7018d93a …

Feb 28, 2024
CVE-2021-46985
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: scan: Fix a memory leak in an error handling path If 'acpi_device_set_name()' fails, we …

Feb 28, 2024
CVE-2021-46983
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: Fix NULL deref when SEND is completed with error When running some traffic and …

Feb 28, 2024
CVE-2021-46982
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix race condition of overwrite vs truncate pos_fsstress testcase complains a panic as …

Feb 28, 2024
CVE-2021-46981
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nbd: Fix NULL pointer in flush_workqueue Open /dev/nbdX first, the config_refs will be 1 and …

Feb 28, 2024
CVE-2021-46979
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: core: fix ioctl handlers removal Currently ioctl handlers are removed twice. For the first …

Feb 28, 2024
CVE-2021-46977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Disable preemption when probing user return MSRs Disable preemption when probing a user …

Feb 28, 2024
CVE-2021-46976
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix crash in auto_retire The retire logic uses the 2 lower bits of the …

Feb 28, 2024
CVE-2020-36787
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: fix clock handling logic Video engine uses eclk and vclk for its clock …

Feb 28, 2024
CVE-2020-36786
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: [next] staging: media: atomisp: fix memory leak of object flash In the case where …

Feb 28, 2024
CVE-2020-36784
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected …

Feb 28, 2024
CVE-2020-36783
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: img-scb: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected …

Feb 28, 2024
CVE-2020-36782
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: imx-lpi2c: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected …

Feb 28, 2024
CVE-2020-36781
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix reference leak when pm_runtime_get_sync fails In i2c_imx_xfer() and i2c_imx_remove(), the pm reference …

Feb 28, 2024
CVE-2020-36780
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: sprd: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected …

Feb 28, 2024
CVE-2020-36779
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: stm32f7: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected …

Feb 28, 2024
CVE-2020-36778
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: xiic: fix reference leak when pm_runtime_get_sync fails The PM reference count is not expected …

Feb 28, 2024
CVE-2024-27913
6.5 MEDIUM

ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA …

Feb 28, 2024
CVE-2024-1943
4.3 MEDIUM

The Yuki theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 1.3.14. This is due to missing or …

Feb 28, 2024
CVE-2024-1568
6.4 MEDIUM

The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. This …

Feb 28, 2024
CVE-2024-1388
4.3 MEDIUM

The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_customizer_options() function in all versions …

Feb 28, 2024
CVE-2024-22723
4.9 MEDIUM

Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond …

Feb 28, 2024
CVE-2024-0550
6.5 MEDIUM

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user …

Feb 28, 2024
CVE-2023-50303
6.1 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 28, 2024
CVE-2024-1932
4.8 MEDIUM

Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout

Feb 28, 2024
CVE-2024-1892
6.5 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By …

Feb 28, 2024
CVE-2024-26302
4.8 MEDIUM

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A …

Feb 27, 2024
CVE-2024-26301
6.5 MEDIUM

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A …

Feb 27, 2024
CVE-2024-26300
6.6 MEDIUM

A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against …

Feb 27, 2024
CVE-2024-26542
6.1 MEDIUM

Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload …

Feb 27, 2024
CVE-2024-26299
6.6 MEDIUM

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack …

Feb 27, 2024
CVE-2021-46974
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix masking negation logic upon negative dst register The negation logic for the case …

Feb 27, 2024
CVE-2021-46972
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ovl: fix leaked dentry Since commit 6815f479ca90 ("ovl: use only uppermetacopy state in ovl_lookup()"), overlayfs …

Feb 27, 2024
CVE-2021-46970
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: pci_generic: Remove WQ_MEM_RECLAIM flag from state workqueue A recent change created a dedicated …

Feb 27, 2024
CVE-2021-46968
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: fix zcard and zqueue hot-unplug memleak Tests with kvm and a kmemdebug kernel showed, …

Feb 27, 2024
CVE-2021-46967
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix vm_flags for virtqueue doorbell mapping The virtqueue doorbell is usually implemented via registeres …

Feb 27, 2024
CVE-2021-46964
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reserve extra IRQ vectors Commit a6dcfe08487e ("scsi: qla2xxx: Limit interrupt vectors to number …

Feb 27, 2024
CVE-2021-46963
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand() RIP: 0010:kmem_cache_free+0xfa/0x1b0 Call Trace: qla2xxx_mqueuecommand+0x2b5/0x2c0 [qla2xxx] scsi_queue_rq+0x5e2/0xa40 __blk_mq_try_issue_directly+0x128/0x1d0 blk_mq_request_issue_directly+0x4e/0xb0 …

Feb 27, 2024
CVE-2021-46962
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: uniphier-sd: Fix a resource leak in the remove function A 'tmio_mmc_host_free()' call is missing …

Feb 27, 2024
CVE-2021-46961
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3: Do not enable irqs when handling spurious interrups We triggered the following error while …

Feb 27, 2024
CVE-2021-46960
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: Return correct error code from smb2_get_enc_key Avoid a warning if the error percolates back …

Feb 27, 2024
CVE-2021-46958
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race between transaction aborts and fsyncs leading to use-after-free There is a race …

Feb 27, 2024
CVE-2021-46957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv/kprobe: fix kernel panic when invoking sys_read traced by kprobe The execution of sys_read end …

Feb 27, 2024
CVE-2021-46956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the same tag to qemu, …

Feb 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.