CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7202
6.1 MEDIUM

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such …

Feb 27, 2024
CVE-2023-7198
4.3 MEDIUM

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete …

Feb 27, 2024
CVE-2023-7167
6.1 MEDIUM

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2023-7115
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 27, 2024
CVE-2021-46920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix clobbering of SWERR overflow bit on writeback Current code blindly writes over …

Feb 27, 2024
CVE-2021-46919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq size store permission state WQ size can only be changed when …

Feb 27, 2024
CVE-2021-46918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: clear MSIX permission entry on shutdown Add disabling/clearing of MSIX permission entries on …

Feb 27, 2024
CVE-2021-46917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround where wq …

Feb 27, 2024
CVE-2021-46916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: Fix NULL pointer dereference in ethtool loopback test The ixgbe driver currently generates a …

Feb 27, 2024
CVE-2021-46915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_limit: avoid possible divide error in nft_limit_init div_u64() divides u64 by u32. nft_limit_init() wants …

Feb 27, 2024
CVE-2021-46914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix unbalanced device enable/disable in suspend/resume pci_disable_device() called in __ixgbe_shutdown() decreases dev->enable_cnt by 1. …

Feb 27, 2024
CVE-2021-46913
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: clone set element expression template memcpy() breaks when using connlimit in set elements. …

Feb 27, 2024
CVE-2021-46912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Make tcp_allowed_congestion_control readonly in non-init netns Currently, tcp_allowed_congestion_control is global and writable; writing to …

Feb 27, 2024
CVE-2021-46911
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ch_ktls: Fix kernel panic Taking page refcount is not ideal and causes kernel panic sometimes. …

Feb 27, 2024
CVE-2021-46910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: 9063/1: mm: reduce maximum number of CPUs if DEBUG_KMAP_LOCAL is enabled The debugging code …

Feb 27, 2024
CVE-2021-46909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: footbridge: fix PCI interrupt mapping Since commit 30fdfb929e82 ("PCI: Add a call to pci_assign_irq() …

Feb 27, 2024
CVE-2021-46908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Use correct permission flag for mixed signed bounds arithmetic We forbid adding unknown scalars …

Feb 27, 2024
CVE-2024-1687
5.4 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to a missing …

Feb 27, 2024
CVE-2024-1686
4.3 MEDIUM

The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, …

Feb 27, 2024
CVE-2024-1323
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type Grid Widget Title in all versions …

Feb 27, 2024
CVE-2023-7033
5.3 MEDIUM

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface …

Feb 27, 2024
CVE-2024-24099
5.4 MEDIUM

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

Feb 27, 2024
CVE-2024-25166
6.1 MEDIUM

Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfile action parameter in the controller.php file.

Feb 27, 2024
CVE-2024-24720
5.3 MEDIUM

An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a …

Feb 27, 2024
CVE-2024-22543
6.1 MEDIUM

An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* …

Feb 27, 2024
CVE-2024-24721
6.5 MEDIUM

An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker …

Feb 27, 2024
CVE-2024-27093
4.6 MEDIUM

Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a …

Feb 26, 2024
CVE-2024-1899
5.3 MEDIUM

An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.

Feb 26, 2024
CVE-2024-25770
4.3 MEDIUM

libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.

Feb 26, 2024
CVE-2021-46906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report …

Feb 26, 2024
CVE-2020-36775
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential deadlock like …

Feb 26, 2024
CVE-2024-27087
4.6 MEDIUM

Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link …

Feb 26, 2024
CVE-2024-25767
6.5 MEDIUM

nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

Feb 26, 2024
CVE-2024-27350
5.9 MEDIUM

Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third …

Feb 26, 2024
CVE-2024-26606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)poll mode, threads often depend on I/O events …

Feb 26, 2024
CVE-2024-26605
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a potential …

Feb 26, 2024
CVE-2024-26604
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whether ktype is NULL" This reverts commit 1b28cb81dab7c1eedc6034206f4e8d644046ad31. It …

Feb 26, 2024
CVE-2024-26603
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to fault in xsave buffer Before this change, …

Feb 26, 2024
CVE-2024-26602
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems, sys_membarrier can be very …

Feb 26, 2024
CVE-2024-26601
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit …

Feb 26, 2024
CVE-2024-26600
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP If the external phy working together …

Feb 26, 2024
CVE-2024-26468
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26467
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26466
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26465
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending …

Feb 26, 2024
CVE-2024-25763
5.5 MEDIUM

openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

Feb 26, 2024
CVE-2024-25410
6.5 MEDIUM

flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.

Feb 26, 2024
CVE-2024-25344
6.1 MEDIUM

Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, …

Feb 26, 2024
CVE-2024-25082
6.5 MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Feb 26, 2024
CVE-2024-25081
4.2 MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.