CVE Database

59526+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27841
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be …

May 14, 2024
CVE-2024-27834
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS …

May 14, 2024
CVE-2024-27827
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to …

May 14, 2024
CVE-2024-27821
4.7 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A …

May 14, 2024
CVE-2024-27816
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. …

May 14, 2024
CVE-2024-27810
5.5 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, …

May 14, 2024
CVE-2024-27804
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, …

May 14, 2024
CVE-2024-27789
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS …

May 14, 2024
CVE-2024-27460
6.7 MEDIUM

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

May 14, 2024
CVE-2024-27400
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace …

May 14, 2024
CVE-2024-27399
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). …

May 14, 2024
CVE-2024-27393
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit …

May 14, 2024
CVE-2024-27282
6.6 MEDIUM

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary …

May 14, 2024
CVE-2024-27281
4.5 MEDIUM

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as …

May 14, 2024
CVE-2024-27269
6.8 MEDIUM

IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.

May 14, 2024
CVE-2024-26306
5.9 MEDIUM

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This …

May 14, 2024
CVE-2024-25662
6.1 MEDIUM

Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.

May 14, 2024
CVE-2024-24157
6.1 MEDIUM

Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

May 14, 2024
CVE-2024-23236
5.5 MEDIUM

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.

May 14, 2024
CVE-2024-23229
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.5. A …

May 14, 2024
CVE-2024-22910
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.

May 14, 2024
CVE-2024-22345
6.2 MEDIUM

IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM …

May 14, 2024
CVE-2024-22344
6.1 MEDIUM

IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in …

May 14, 2024
CVE-2024-22343
4.0 MEDIUM

IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: …

May 14, 2024
CVE-2024-1693
4.3 MEDIUM

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category …

May 14, 2024
CVE-2024-1467
4.3 MEDIUM

The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

May 14, 2024
CVE-2024-1230
4.3 MEDIUM

The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or …

May 14, 2024
CVE-2024-1229
5.3 MEDIUM

The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions …

May 14, 2024
CVE-2024-1166
6.4 MEDIUM

The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hover Effects Widget in all …

May 14, 2024
CVE-2024-0445
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, …

May 14, 2024
CVE-2024-0100
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this …

May 14, 2024
CVE-2024-0098
5.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue …

May 14, 2024
CVE-2024-0088
5.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a …

May 14, 2024
CVE-2023-6688
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google …

May 14, 2024
CVE-2023-6682
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

May 14, 2024
CVE-2023-6327
5.3 MEDIUM

The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in …

May 14, 2024
CVE-2023-5971
4.8 MEDIUM

The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege …

May 14, 2024
CVE-2023-5447
5.5 MEDIUM

Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics …

May 14, 2024
CVE-2023-5052
6.3 MEDIUM

vulnerability in Uniform Server Zero, version 10.2.5, consisting of an XSS through the /us_extra/phpinfo.php page. This vulnerability could allow a remote user to send a …

May 14, 2024
CVE-2023-52721
6.2 MEDIUM

The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.

May 14, 2024
CVE-2023-52720
4.1 MEDIUM

Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52656
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support …

May 14, 2024
CVE-2023-52655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet …

May 14, 2024
CVE-2023-52654
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for …

May 14, 2024
CVE-2023-52384
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52383
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-50718
6.5 MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on …

May 14, 2024
CVE-2023-50717
5.7 MEDIUM

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with …

May 14, 2024
CVE-2023-43040
6.5 MEDIUM

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM …

May 14, 2024
CVE-2023-42955
4.9 MEDIUM

Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.