CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0403
6.5 MEDIUM

Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.

Mar 1, 2024
CVE-2021-47067
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc/tegra: regulators: Fix locking up when voltage-spread is out of range Fix voltage coupler lockup …

Feb 29, 2024
CVE-2021-47066
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: async_xor: increase src_offs when dropping destination page Now we support sharing one page if PAGE_SIZE …

Feb 29, 2024
CVE-2021-47064
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could …

Feb 29, 2024
CVE-2021-47062
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Use online_vcpus, not created_vcpus, to iterate over vCPUs Use the kvm_for_each_vcpu() helper to …

Feb 29, 2024
CVE-2021-47060
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: Stop looking for coalesced MMIO zones if the bus is destroyed Abort the walk …

Feb 29, 2024
CVE-2021-47059
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - fix result memory leak on error path This patch fixes a memory …

Feb 29, 2024
CVE-2021-47057
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of object d when dma_iv fails to map In …

Feb 29, 2024
CVE-2021-47056
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - ADF_STATUS_PF_RUNNING should be set after adf_dev_init ADF_STATUS_PF_RUNNING is (only) used and checked …

Feb 29, 2024
CVE-2021-47055
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection …

Feb 29, 2024
CVE-2021-47054
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: qcom: Put child node before return Put child node before return to fix potential …

Feb 29, 2024
CVE-2021-47020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soundwire: stream: fix memory leak in stream config error path When stream config is failed, …

Feb 29, 2024
CVE-2021-47016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: m68k: mvme147,mvme16x: Don't wipe PCC timer config bits Don't clear the timer 1 configuration bits …

Feb 29, 2024
CVE-2024-2009
5.3 MEDIUM

A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_login_submit_form of the file …

Feb 29, 2024
CVE-2024-27662
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

Feb 29, 2024
CVE-2024-27661
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27660
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

Feb 29, 2024
CVE-2024-27659
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-27658
6.5 MEDIUM

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted …

Feb 29, 2024
CVE-2024-24246
5.5 MEDIUM

Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.

Feb 29, 2024
CVE-2024-0068
5.5 MEDIUM

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue affects Workforce Access: before 8.7.1.

Feb 29, 2024
CVE-2023-52485
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a command [Why] We can hang in place trying to …

Feb 29, 2024
CVE-2024-2001
5.5 MEDIUM

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store …

Feb 29, 2024
CVE-2024-26607
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely …

Feb 29, 2024
CVE-2024-27906
5.9 MEDIUM

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have …

Feb 29, 2024
CVE-2024-1953
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, …

Feb 29, 2024
CVE-2024-1942
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an …

Feb 29, 2024
CVE-2024-1619
6.1 MEDIUM

Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an …

Feb 29, 2024
CVE-2024-1888
4.3 MEDIUM

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members …

Feb 29, 2024
CVE-2024-24988
4.3 MEDIUM

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very …

Feb 29, 2024
CVE-2024-23493
4.3 MEDIUM

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that …

Feb 29, 2024
CVE-2024-1887
4.3 MEDIUM

Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the …

Feb 29, 2024
CVE-2024-25594
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress Development MyWaze allows Stored XSS.This issue affects MyWaze: from n/a through …

Feb 29, 2024
CVE-2024-1982
6.5 MEDIUM

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() …

Feb 29, 2024
CVE-2024-1978
5.5 MEDIUM

The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes …

Feb 29, 2024
CVE-2024-25098
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB oEmbed HTML5 Audio – with Cache Support allows Stored XSS.This …

Feb 29, 2024
CVE-2024-25094
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects …

Feb 29, 2024
CVE-2024-23501
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: from n/a …

Feb 29, 2024
CVE-2024-1977
4.4 MEDIUM

The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input …

Feb 29, 2024
CVE-2024-1976
4.3 MEDIUM

The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing …

Feb 29, 2024
CVE-2024-1434
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Media Alt Renamer allows Stored XSS.This issue affects Media Alt Renamer: …

Feb 29, 2024
CVE-2023-52484
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Fix soft lockup triggered by arm_smmu_mm_invalidate_range When running an SVA case, the following soft …

Feb 29, 2024
CVE-2023-52481
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivileged load workaround Implement the workaround for ARM Cortex-A520 erratum …

Feb 29, 2024
CVE-2023-52478
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect hidpp_connect_event() has *four* time-of-check vs time-of-use …

Feb 29, 2024
CVE-2023-52477
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: hub: Guard against accesses to uninitialized BOS descriptors Many functions in drivers/usb/core/hub.c and drivers/usb/core/hub.h …

Feb 29, 2024
CVE-2023-52476
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/x86/lbr: Filter vsyscall addresses We found that a panic can occur when a vsyscall is …

Feb 29, 2024
CVE-2023-47874
5.4 MEDIUM

Missing Authorization vulnerability in Perfmatters.This issue affects Perfmatters: from n/a through 2.1.6.

Feb 29, 2024
CVE-2024-1435
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.6.

Feb 29, 2024
CVE-2024-1341
4.9 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 …

Feb 29, 2024
CVE-2023-51696
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.