CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA Replace the fake VLA …

Nov 5, 2024
CVE-2024-50133
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Don't crash in stack_top() for tasks without vDSO Not all tasks have a vDSO …

Nov 5, 2024
CVE-2024-50132
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix MAX_TRACE_ARGS limit handling When creating a trace_probe we would set nr_args prior to …

Nov 5, 2024
CVE-2024-50131
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tracing: Consider the NULL character when validating the event length strlen() returns a string length …

Nov 5, 2024
CVE-2024-50130
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: must hold reference on net namespace BUG: KASAN: slab-use-after-free in __nf_unregister_net_hook+0x640/0x6b0 Read of …

Nov 5, 2024
CVE-2024-50129
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: pse-pd: Fix out of bound for loop Adjust the loop limit to prevent out-of-bounds …

Nov 5, 2024
CVE-2024-50128
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: wwan: fix global oob in wwan_rtnl_policy The variable wwan_rtnl_link_ops assign a *bigger* maxtype which …

Nov 5, 2024
CVE-2024-50127
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix use-after-free in taprio_change() In 'taprio_change()', 'admin' pointer may become dangling due to …

Nov 5, 2024
CVE-2024-50126
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: sched: use RCU read-side critical section in taprio_dump() Fix possible use-after-free in 'taprio_dump()' by …

Nov 5, 2024
CVE-2024-50125
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix UAF on sco_sock_timeout conn->sk maybe have been unlinked/freed while waiting for sco_conn_lock …

Nov 5, 2024
CVE-2024-50124
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix UAF on iso_sock_timeout conn->sk maybe have been unlinked/freed while waiting for iso_conn_lock …

Nov 5, 2024
CVE-2024-50123
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Add the missing BPF_LINK_TYPE invocation for sockmap There is an out-of-bounds read in bpf_link_show_fdinfo() …

Nov 5, 2024
CVE-2024-50122
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Hold rescan lock while adding devices during host probe Since adding the PCI power …

Nov 5, 2024
CVE-2024-50121
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net In the normal case, when we excute …

Nov 5, 2024
CVE-2024-50120
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: Handle kstrdup failures for passwords In smb3_reconfigure(), after duplicating ctx->password and ctx->password2 with …

Nov 5, 2024
CVE-2024-50119
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: fix warning when destroy 'cifs_io_request_pool' There's a issue as follows: WARNING: CPU: 1 PID: …

Nov 5, 2024
CVE-2024-50118
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject ro->rw reconfiguration if there are hard ro requirements [BUG] Syzbot reports the following …

Nov 5, 2024
CVE-2024-50117
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd: Guard against bad data for ATIF ACPI method If a BIOS provides bad data …

Nov 5, 2024
CVE-2024-50116
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug due to missing clearing of buffer delay flag Syzbot reported that …

Nov 5, 2024
CVE-2024-50115
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from …

Nov 5, 2024
CVE-2024-50114
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unregister redistributor for failed vCPU creation Alex reports that syzkaller has managed to …

Nov 5, 2024
CVE-2024-50113
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix invalid port index for parent device In a commit 24b7f8e5cd65 ("firewire: core: …

Nov 5, 2024
CVE-2024-50112
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/lam: Disable ADDRESS_MASKING in most cases Linear Address Masking (LAM) has a weakness related to …

Nov 5, 2024
CVE-2024-50111
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable IRQ if do_ale() triggered in irq-enabled context Unaligned access exception can be triggered …

Nov 5, 2024
CVE-2024-50110
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix one more kernel-infoleak in algo dumping During fuzz testing, the following issue was …

Nov 5, 2024
CVE-2024-50109
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null ptr dereference in raid10_size() In raid10_run() if raid10_set_queue_limits() succeed, the return value …

Nov 5, 2024
CVE-2024-50108
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too Stuart Hayhurst has found that both at …

Nov 5, 2024
CVE-2024-50107
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid addresses Commit 50c6dbdfd16e ("x86/ioremap: Improve iounmap() address …

Nov 5, 2024
CVE-2024-50106
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix race between laundromat and free_stateid There is a race between laundromat handling of …

Nov 5, 2024
CVE-2024-50105
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: sc7280: Fix missing Soundwire runtime stream alloc Commit 15c7fab0e047 ("ASoC: qcom: Move Soundwire …

Nov 5, 2024
CVE-2024-50104
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: sdm845: add missing soundwire runtime stream alloc During the migration of Soundwire runtime …

Nov 5, 2024
CVE-2024-50103
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe() A devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could possibly return NULL …

Nov 5, 2024
CVE-2024-50102
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a …

Nov 5, 2024
CVE-2024-50101
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices Previously, the domain_context_clear() function incorrectly called pci_for_each_dma_alias() to …

Nov 5, 2024
CVE-2024-50100
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: dummy-hcd: Fix "task hung" problem The syzbot fuzzer has been encountering "task hung" …

Nov 5, 2024
CVE-2024-50099
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: probes: Remove broken LDR (literal) uprobe support The simulate_ldr_literal() and simulate_ldrsw_literal() functions are unsafe …

Nov 5, 2024
CVE-2024-50098
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Set SDEV_OFFLINE when UFS is shut down There is a history of …

Nov 5, 2024
CVE-2024-9579
7.5 HIGH

A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability …

Nov 5, 2024
CVE-2024-51362
6.5 MEDIUM

The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP …

Nov 5, 2024
CVE-2024-51132
9.8 CRITICAL

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted …

Nov 5, 2024
CVE-2024-50097
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fec: don't save PTP state if PTP is unsupported Some platforms (such as i.MX25 …

Nov 5, 2024
CVE-2024-50096
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error The `nouveau_dmem_copy_one` function ensures that the copy …

Nov 5, 2024
CVE-2024-50095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Improve handling of timed out WRs of mad agent Current timeout handler of mad …

Nov 5, 2024
CVE-2024-50094
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sfc: Don't invoke xdp_do_flush() from netpoll. Yury reported a crash in the sfc driver originated …

Nov 5, 2024
CVE-2024-50093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int340x: processor: Fix warning during module unload The processor_thermal driver uses pcim_device_enable() to …

Nov 5, 2024
CVE-2024-50092
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: net: netconsole: fix wrong warning A warning is triggered when there is insufficient space in …

Nov 5, 2024
CVE-2024-50091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm vdo: don't refer to dedupe_context after releasing it Clear the dedupe_context pointer in a …

Nov 5, 2024
CVE-2024-50090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix overflow in oa batch buffer By default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch …

Nov 5, 2024
CVE-2024-50089

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 5, 2024
CVE-2024-49522
7.8 HIGH

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Nov 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.