CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46953
6.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: GTDT: Don't corrupt interrupt mappings on watchdow probe failure When failing the driver probe …

Feb 27, 2024
CVE-2021-46951
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: efi: Use local variable for calculating final log size When tpm_read_log_efi is called multiple …

Feb 27, 2024
CVE-2021-46949
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX flush done handling We're starting from a …

Feb 27, 2024
CVE-2021-46948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX event handling We're starting from a TXQ …

Feb 27, 2024
CVE-2021-46947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: adjust efx->xdp_tx_queue_count with the real number of initialized queues efx->xdp_tx_queue_count is initially initialized to …

Feb 27, 2024
CVE-2021-46945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: always panic when errors=panic is specified Before commit 014c9caa29d3 ("ext4: make ext4_abort() use __ext4_error()"), …

Feb 27, 2024
CVE-2021-46944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: staging/intel-ipu3: Fix memory leak in imu_fmt We are losing the reference to an allocated …

Feb 27, 2024
CVE-2021-46942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix shared sqpoll cancellation hangs [ 736.982891] INFO: task iou-sqp-4294:4295 blocked for more than …

Feb 27, 2024
CVE-2021-46941
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: Do core softreset when switch mode According to the programming guide, to …

Feb 27, 2024
CVE-2021-46940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix offset overflow issue in index converting The idx_to_offset() function returns type int …

Feb 27, 2024
CVE-2021-46939
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Restructure trace_clock_global() to never block It was reported that a fix to the ring …

Feb 27, 2024
CVE-2020-36777
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_free() dvb_media_device_free() is leaking memory. Free `dvbdev->adapter->conn` before setting …

Feb 27, 2024
CVE-2020-36776
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue Slab OOB issue is scanned by KASAN in cpu_power_to_freq(). If …

Feb 27, 2024
CVE-2024-25841
5.9 MEDIUM

In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.

Feb 27, 2024
CVE-2024-21742
5.3 MEDIUM

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to …

Feb 27, 2024
CVE-2024-1926
6.3 MEDIUM

A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown …

Feb 27, 2024
CVE-2024-1925
5.0 MEDIUM

A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipulation leads …

Feb 27, 2024
CVE-2024-1924
6.3 MEDIUM

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /get_membership_amount.php. …

Feb 27, 2024
CVE-2023-50380
6.5 MEDIUM

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie …

Feb 27, 2024
CVE-2023-48682
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Feb 27, 2024
CVE-2023-48681
6.1 MEDIUM

Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Feb 27, 2024
CVE-2023-48680
5.5 MEDIUM

Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.

Feb 27, 2024
CVE-2023-48679
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build …

Feb 27, 2024
CVE-2023-48678
5.5 MEDIUM

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Feb 27, 2024
CVE-2024-26144
5.3 MEDIUM

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends …

Feb 27, 2024
CVE-2024-26143
6.1 MEDIUM

Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, …

Feb 27, 2024
CVE-2024-25399
6.1 MEDIUM

Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.

Feb 27, 2024
CVE-2024-1923
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as critical. Affected by this issue is the function delete_class/delete_student of the …

Feb 27, 2024
CVE-2024-1921
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The …

Feb 27, 2024
CVE-2024-1920
5.6 MEDIUM

A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects the function handle of the file …

Feb 27, 2024
CVE-2024-1918
4.7 MEDIUM

A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affected by this vulnerability is an unknown …

Feb 27, 2024
CVE-2024-1912
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1910
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1909
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1907
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1906
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1653
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up …

Feb 27, 2024
CVE-2024-1652
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions …

Feb 27, 2024
CVE-2024-1650
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions …

Feb 27, 2024
CVE-2024-1649
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions …

Feb 27, 2024
CVE-2021-46937
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: fix 'struct pid' leaks in 'dbgfs_target_ids_write()' DAMON debugfs interface increases the reference counts of …

Feb 27, 2024
CVE-2021-46935
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d ("android: binder: Move buffer …

Feb 27, 2024
CVE-2021-46933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear. ffs_data_clear is indirectly called from both ffs_fs_kill_sb and …

Feb 27, 2024
CVE-2021-46932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This …

Feb 27, 2024
CVE-2021-46931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Wrap the tx reporter dump callback to extract the sq Function mlx5e_tx_reporter_dump_sq() casts its …

Feb 27, 2024
CVE-2021-46930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: fix list_head check warning This is caused by uninitialization of list_head. BUG: KASAN: …

Feb 27, 2024
CVE-2021-46929
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: use call_rcu to free endpoint This patch is to delay the endpoint free by …

Feb 27, 2024
CVE-2021-46928
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Clear stale IIR value on instruction access rights trap When a trap 7 (Instruction …

Feb 27, 2024
CVE-2021-46927
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nitro_enclaves: Use get_user_pages_unlocked() call to handle mmap assert After commit 5b78ed24e8ec ("mm/pagemap: add mmap_assert_locked() annotations …

Feb 27, 2024
CVE-2021-46926
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: harden detection of controller The existing code currently sets a pointer to …

Feb 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.