CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30953
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Apr 17, 2024
CVE-2024-3914
6.5 MEDIUM

Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 17, 2024
CVE-2024-30988
6.8 MEDIUM

Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive …

Apr 17, 2024
CVE-2024-30987
6.8 MEDIUM

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive …

Apr 17, 2024
CVE-2024-30986
6.5 MEDIUM

Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" …

Apr 17, 2024
CVE-2024-30951
6.1 MEDIUM

FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php.

Apr 17, 2024
CVE-2023-5407
5.9 MEDIUM

Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading …

Apr 17, 2024
CVE-2023-5406
5.9 MEDIUM

Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations …

Apr 17, 2024
CVE-2023-5405
5.9 MEDIUM

Server information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. See Honeywell …

Apr 17, 2024
CVE-2023-5398
5.9 MEDIUM

Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for …

Apr 17, 2024
CVE-2024-32320
5.9 MEDIUM

Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.

Apr 17, 2024
CVE-2024-32316
6.5 MEDIUM

Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.

Apr 17, 2024
CVE-2024-31463
4.7 MEDIUM

Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled by the `IRONIC_REVERSE_PROXY_SETUP` variable set to `true`, …

Apr 17, 2024
CVE-2024-30979
5.9 MEDIUM

Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.

Apr 17, 2024
CVE-2024-26920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/trigger: Fix to return error if failed to alloc snapshot Fix register_snapshot_trigger() to return error …

Apr 17, 2024
CVE-2024-26919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: Fix debugfs directory leak The ULPI per-device debugfs root is named after the …

Apr 17, 2024
CVE-2024-26918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix active state requirement in PME polling The commit noted in fixes added a …

Apr 17, 2024
CVE-2024-26917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212. This commit …

Apr 17, 2024
CVE-2024-26916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: flush any delayed gfxoff on suspend entry" commit ab4750332dbe ("drm/amdgpu/sdma5.2: add begin/end_use ring …

Apr 17, 2024
CVE-2024-26915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reset IH OVERFLOW_CLEAR bit Allows us to detect subsequent IH ring buffer overflows as …

Apr 17, 2024
CVE-2024-26912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix several DMA buffer leaks Nouveau manages GSP-RM DMA buffers with nvkm_gsp_mem objects. Several …

Apr 17, 2024
CVE-2024-26910
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix performance regression in swap operation The patch "netfilter: ipset: fix race condition …

Apr 17, 2024
CVE-2023-52645
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with …

Apr 17, 2024
CVE-2024-3825
4.3 MEDIUM

Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration

Apr 17, 2024
CVE-2024-29035
4.1 MEDIUM

Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. …

Apr 17, 2024
CVE-2024-32315
4.7 MEDIUM

Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32311
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32306
5.7 MEDIUM

Tenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32302
6.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32290
6.7 MEDIUM

Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.

Apr 17, 2024
CVE-2024-32288
6.3 MEDIUM

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.

Apr 17, 2024
CVE-2024-32287
6.5 MEDIUM

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.

Apr 17, 2024
CVE-2024-32282
6.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

Apr 17, 2024
CVE-2024-32313
6.5 MEDIUM

Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32312
5.7 MEDIUM

Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the adslPwd parameter of the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-30952
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in PESCMS-TEAM v2.3.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Apr 17, 2024
CVE-2023-6805
6.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request …

Apr 17, 2024
CVE-2023-45209
5.3 MEDIUM

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead …

Apr 17, 2024
CVE-2023-43491
5.3 MEDIUM

An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead …

Apr 17, 2024
CVE-2023-40146
6.8 MEDIUM

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to …

Apr 17, 2024
CVE-2024-3908
6.3 MEDIUM

A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the …

Apr 17, 2024
CVE-2024-3333
6.4 MEDIUM

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, …

Apr 17, 2024
CVE-2024-26909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink_altmode: fix drm bridge use-after-free A recent DRM series purporting to simplify support …

Apr 17, 2024
CVE-2024-26906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() When trying to use copy_from_kernel_nofault() to read vsyscall …

Apr 17, 2024
CVE-2024-26903
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security During our fuzz testing of the connection and disconnection …

Apr 17, 2024
CVE-2024-26902
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: RISCV: Fix panic on pmu overflow handler (1 << idx) of int is not …

Apr 17, 2024
CVE-2024-26901
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak syzbot identified a kernel information leak vulnerability in do_sys_name_to_handle() …

Apr 17, 2024
CVE-2024-26900
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md: fix kmemleak of rdev->serial If kobject_add() is fail in bind_rdev_to_array(), 'rdev->serial' will be alloc …

Apr 17, 2024
CVE-2024-26899
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix deadlock between bd_link_disk_holder and partition scan 'open_mutex' of gendisk is used to protect …

Apr 17, 2024
CVE-2024-26897
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete The ath9k_wmi_event_tasklet() used in ath9k_htc …

Apr 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.