CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40398
8.8 HIGH

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and …

Jul 29, 2024
CVE-2023-40396
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. …

Jul 29, 2024
CVE-2019-6185

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-6174

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-6164

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-6162

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2017-3769

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2017-3766

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2017-3755

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2024-6620
3.5 LOW

Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to …

Jul 29, 2024
CVE-2022-4038

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2022-48185

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-19761

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-19760

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-19759

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2024-6578
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically …

Jul 29, 2024
CVE-2024-37859
6.1 MEDIUM

Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.

Jul 29, 2024
CVE-2024-37858
9.8 CRITICAL

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

Jul 29, 2024
CVE-2024-37857
8.8 HIGH

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.

Jul 29, 2024
CVE-2024-37856
5.4 MEDIUM

Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields …

Jul 29, 2024
CVE-2024-28806
7.5 HIGH

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

Jul 29, 2024
CVE-2024-28805
9.1 CRITICAL

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

Jul 29, 2024
CVE-2024-28804
7.1 HIGH

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.

Jul 29, 2024
CVE-2024-6727
5.4 MEDIUM

A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application.

Jul 29, 2024
CVE-2024-6726
8.8 HIGH

Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).

Jul 29, 2024
CVE-2024-42098
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ecdh - explicitly zeroize private_key private_key is overwritten with the key parameter passed in …

Jul 29, 2024
CVE-2024-42097
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: emux: improve patch ioctl data validation In load_data(), make the validation of and skipping …

Jul 29, 2024
CVE-2024-42096
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86: stop playing stack games in profile_pc() The 'profile_pc()' function is used for timer-based profiling, …

Jul 29, 2024
CVE-2024-42095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_omap: Implementation of Errata i2310 As per Errata i2310[0], Erroneous timeout can be triggered, …

Jul 29, 2024
CVE-2024-42094
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/iucv: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask …

Jul 29, 2024
CVE-2024-42093
7.3 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask …

Jul 29, 2024
CVE-2024-42092
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: gpio: davinci: Validate the obtained number of IRQs Value of pdata->gpio_unbanked is taken from Device …

Jul 29, 2024
CVE-2024-42091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Check pat.ops before dumping PAT settings We may leave pat.ops unset when running on …

Jul 29, 2024
CVE-2024-6748
8.3 HIGH

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.

Jul 29, 2024
CVE-2024-42090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER In create_pinctrl(), pinctrl_maps_mutex is acquired before calling …

Jul 29, 2024
CVE-2024-42089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl-asoc-card: set priv->pdev before using it priv->pdev pointer was set after being used in …

Jul 29, 2024
CVE-2024-42088
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: …

Jul 29, 2024
CVE-2024-42087
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep The ilitek-ili9881c controls the reset GPIO …

Jul 29, 2024
CVE-2024-42086
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: bme680: Fix overflows in compensate() functions There are cases in the compensate functions …

Jul 29, 2024
CVE-2024-42085
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock When …

Jul 29, 2024
CVE-2024-42084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ftruncate: pass a signed offset The old ftruncate() syscall, using the 32-bit off_t misses a …

Jul 29, 2024
CVE-2024-33365
7.5 HIGH

Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the Virtual_Data_Check function in the bin/httpd component.

Jul 29, 2024
CVE-2024-42083
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ionic: fix kernel panic due to multi-buffer handling Currently, the ionic_run_xdp() doesn't handle multi-buffer packets …

Jul 29, 2024
CVE-2024-42082
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xdp: Remove WARN() from __xdp_reg_mem_model() syzkaller reports a warning in __xdp_reg_mem_model(). The warning occurs only …

Jul 29, 2024
CVE-2024-42081
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_devcoredump: Check NULL before assignments Assign 'xe_devcoredump_snapshot *' and 'xe_device *' only if 'coredump' is …

Jul 29, 2024
CVE-2024-42080
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/restrack: Fix potential invalid address access struct rdma_restrack_entry's kern_name was set to KBUILD_MODNAME in ib_create_cq(), …

Jul 29, 2024
CVE-2024-42079
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix NULL pointer dereference in gfs2_log_flush In gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the …

Jul 29, 2024
CVE-2024-42078
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: initialise nfsd_info.mutex early. nfsd_info.mutex can be dereferenced by svc_pool_stats_start() immediately after the new netns …

Jul 29, 2024
CVE-2024-42077
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix DIO failure due to insufficient transaction credits The code in ocfs2_dio_end_io_write() estimates number …

Jul 29, 2024
CVE-2024-42076
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: Initialize unused data in j1939_send_one() syzbot reported kernel-infoleak in raw_recvmsg() [1]. j1939_send_one() …

Jul 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.