CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46925
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix kernel panic caused by race of smc_sock A crash occurs when smc_cdc_tx_handler() tries …

Feb 27, 2024
CVE-2021-46924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device …

Feb 27, 2024
CVE-2021-46923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built …

Feb 27, 2024
CVE-2021-46922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM …

Feb 27, 2024
CVE-2021-46921
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a …

Feb 27, 2024
CVE-2024-1106
6.1 MEDIUM

The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2024-0855
5.3 MEDIUM

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to …

Feb 27, 2024
CVE-2023-7203
6.1 MEDIUM

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as …

Feb 27, 2024
CVE-2023-7202
6.1 MEDIUM

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such …

Feb 27, 2024
CVE-2023-7198
4.3 MEDIUM

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete …

Feb 27, 2024
CVE-2023-7167
6.1 MEDIUM

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2023-7115
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 27, 2024
CVE-2021-46920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix clobbering of SWERR overflow bit on writeback Current code blindly writes over …

Feb 27, 2024
CVE-2021-46919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq size store permission state WQ size can only be changed when …

Feb 27, 2024
CVE-2021-46918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: clear MSIX permission entry on shutdown Add disabling/clearing of MSIX permission entries on …

Feb 27, 2024
CVE-2021-46917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround where wq …

Feb 27, 2024
CVE-2021-46916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: Fix NULL pointer dereference in ethtool loopback test The ixgbe driver currently generates a …

Feb 27, 2024
CVE-2021-46915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: avoid possible divide error in nft_limit_init div_u64() divides u64 by u32. nft_limit_init() wants …

Feb 27, 2024
CVE-2021-46914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix unbalanced device enable/disable in suspend/resume pci_disable_device() called in __ixgbe_shutdown() decreases dev->enable_cnt by 1. …

Feb 27, 2024
CVE-2021-46913
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: clone set element expression template memcpy() breaks when using connlimit in set elements. …

Feb 27, 2024
CVE-2021-46912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Make tcp_allowed_congestion_control readonly in non-init netns Currently, tcp_allowed_congestion_control is global and writable; writing to …

Feb 27, 2024
CVE-2021-46911
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes. …

Feb 27, 2024
CVE-2021-46910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: 9063/1: mm: reduce maximum number of CPUs if DEBUG_KMAP_LOCAL is enabled The debugging code …

Feb 27, 2024
CVE-2021-46909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: footbridge: fix PCI interrupt mapping Since commit 30fdfb929e82 ("PCI: Add a call to pci_assign_irq() …

Feb 27, 2024
CVE-2021-46908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Use correct permission flag for mixed signed bounds arithmetic We forbid adding unknown scalars …

Feb 27, 2024
CVE-2024-1687
5.4 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to a missing …

Feb 27, 2024
CVE-2024-1686
4.3 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, …

Feb 27, 2024
CVE-2024-1323
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions …

Feb 27, 2024
CVE-2023-7033
5.3 MEDIUM

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface …

Feb 27, 2024
CVE-2024-24099
5.4 MEDIUM

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

Feb 27, 2024
CVE-2024-25166
6.1 MEDIUM

Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfile action parameter in the controller.php file.

Feb 27, 2024
CVE-2024-24720
5.3 MEDIUM

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a …

Feb 27, 2024
CVE-2024-22543
6.1 MEDIUM

An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* …

Feb 27, 2024
CVE-2024-24721
6.5 MEDIUM

An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker …

Feb 27, 2024
CVE-2024-27093
4.6 MEDIUM

Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a …

Feb 26, 2024
CVE-2024-1899
5.3 MEDIUM

An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.

Feb 26, 2024
CVE-2024-25770
4.3 MEDIUM

libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.

Feb 26, 2024
CVE-2021-46906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report …

Feb 26, 2024
CVE-2020-36775
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential deadlock like …

Feb 26, 2024
CVE-2024-27087
4.6 MEDIUM

Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link …

Feb 26, 2024
CVE-2024-25767
6.5 MEDIUM

nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

Feb 26, 2024
CVE-2024-27350
5.9 MEDIUM

Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third …

Feb 26, 2024
CVE-2024-26606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)poll mode, threads often depend on I/O events …

Feb 26, 2024
CVE-2024-26605
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a potential …

Feb 26, 2024
CVE-2024-26604
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whether ktype is NULL" This reverts commit 1b28cb81dab7c1eedc6034206f4e8d644046ad31. It …

Feb 26, 2024
CVE-2024-26603
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to fault in xsave buffer Before this change, …

Feb 26, 2024
CVE-2024-26602
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems, sys_membarrier can be very …

Feb 26, 2024
CVE-2024-26601
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit …

Feb 26, 2024
CVE-2024-26600
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP If the external phy working together …

Feb 26, 2024
CVE-2024-26468
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.