CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43875
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Clean up error handling in vpci_scan_bus() Smatch complains about inconsistent NULL checking in …

Aug 21, 2024
CVE-2024-43874
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix null pointer dereference in __sev_snp_shutdown_locked Fix a null pointer dereference induced …

Aug 21, 2024
CVE-2024-43873
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow There are two issues around seqpacket_allow: 1. seqpacket_allow is not initialized …

Aug 21, 2024
CVE-2024-43872
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup under heavy CEQE load CEQEs are handled in interrupt handler currently. …

Aug 21, 2024
CVE-2024-43871
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: devres: Fix memory leakage caused by driver API devm_free_percpu() It will cause memory leakage when …

Aug 21, 2024
CVE-2024-43870
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: Fix event leak upon exit When a task is scheduled out, pending sigtrap deliveries …

Aug 21, 2024
CVE-2024-43869
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: Fix event leak upon exec and file release The perf pending task work is …

Aug 21, 2024
CVE-2024-8023
6.3 MEDIUM

A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to …

Aug 21, 2024
CVE-2024-8022
3.5 LOW

A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This issue affects some unknown processing of the file …

Aug 21, 2024
CVE-2024-43868
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv/purgatory: align riscv_kernel_entry When alignment handling is delegated to the kernel, everything must be word-aligned …

Aug 21, 2024
CVE-2024-43867
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: prime: fix refcount underflow Calling nouveau_bo_ref() on a nouveau_bo without initializing it (and hence …

Aug 21, 2024
CVE-2024-43866
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback There is no point in recovery during device …

Aug 21, 2024
CVE-2024-43865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu code exception …

Aug 21, 2024
CVE-2024-43864
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix CT entry update leaks of modify header context The cited commit allocates a …

Aug 21, 2024
CVE-2024-43863
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a deadlock in dma buf fence polling Introduce a version of the fence …

Aug 21, 2024
CVE-2024-43862
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlock to a mutex The carrier_lock spinlock protects the carrier …

Aug 21, 2024
CVE-2024-22281
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own …

Aug 20, 2024
CVE-2024-43861
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: fix memory leak for not ip packets Free the unused skb when …

Aug 20, 2024
CVE-2024-43403
8.8 HIGH

Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. …

Aug 20, 2024
CVE-2024-43396
5.4 MEDIUM

Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in …

Aug 20, 2024
CVE-2024-42363
8.8 HIGH

Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the …

Aug 20, 2024
CVE-2024-42362
8.8 HIGH

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in …

Aug 20, 2024
CVE-2024-42361
7.5 HIGH

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes …

Aug 20, 2024
CVE-2024-41658
6.1 MEDIUM

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to …

Aug 20, 2024
CVE-2024-41657
8.1 HIGH

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego …

Aug 20, 2024
CVE-2024-7711
4.3 MEDIUM

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a …

Aug 20, 2024
CVE-2024-6800
9.8 CRITICAL

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation …

Aug 20, 2024
CVE-2024-6337
6.5 MEDIUM

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read …

Aug 20, 2024
CVE-2024-41773
6.5 MEDIUM

IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.

Aug 20, 2024
CVE-2024-41659
8.1 HIGH

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set …

Aug 20, 2024
CVE-2024-31842
8.8 HIGH

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string …

Aug 20, 2024
CVE-2024-42619
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com

Aug 20, 2024
CVE-2024-38175
9.6 CRITICAL

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

Aug 20, 2024
CVE-2024-6322
5.4 MEDIUM

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted …

Aug 20, 2024
CVE-2024-42612
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add

Aug 20, 2024
CVE-2024-35214

A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS …

Aug 20, 2024
CVE-2024-43408
6.3 MEDIUM

Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in the html of the post. The vulnerability is …

Aug 20, 2024
CVE-2024-42919
9.8 CRITICAL

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

Aug 20, 2024
CVE-2024-42598
6.7 MEDIUM

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still …

Aug 20, 2024
CVE-2024-40743
6.1 MEDIUM

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

Aug 20, 2024
CVE-2024-27187
7.5 HIGH

Improper Access Controls allows backend users to overwrite their username when disallowed.

Aug 20, 2024
CVE-2024-27186
6.1 MEDIUM

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

Aug 20, 2024
CVE-2024-27185
9.1 CRITICAL

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

Aug 20, 2024
CVE-2024-27184
6.1 MEDIUM

Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

Aug 20, 2024
CVE-2024-43409
6.5 MEDIUM

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and …

Aug 20, 2024
CVE-2024-43406
8.8 HIGH

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL …

Aug 20, 2024
CVE-2024-43404
9.8 CRITICAL

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code …

Aug 20, 2024
CVE-2024-43397
4.3 MEDIUM

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. …

Aug 20, 2024
CVE-2024-43377
5.4 MEDIUM

Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.

Aug 20, 2024
CVE-2024-43376
4.3 MEDIUM

Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This …

Aug 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.