CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36081
9.8 CRITICAL

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that …

May 19, 2024
CVE-2024-36080
9.8 CRITICAL

Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter …

May 19, 2024
CVE-2024-36078
6.7 MEDIUM

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to …

May 19, 2024
CVE-2024-36076
8.8 HIGH

Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user …

May 19, 2024
CVE-2024-36070
7.5 HIGH

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. …

May 19, 2024
CVE-2024-36053
9.0 CRITICAL

In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user …

May 19, 2024
CVE-2024-5101
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file updateproduct.php. …

May 19, 2024
CVE-2024-5100
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Inventory System 1.0. It has been classified as critical. This affects an unknown part of the file tableedit.php. …

May 19, 2024
CVE-2024-35947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >control parser Fix a BUG_ON from 2009. Even if it …

May 19, 2024
CVE-2024-35946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix null pointer access when abort scan During cancel scan we might use …

May 19, 2024
CVE-2024-35945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: phy_device: Prevent nullptr exceptions on ISR If phydev->irq is set unconditionally, check for …

May 19, 2024
CVE-2024-35944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host() Syzkaller hit 'WARNING in dg_dispatch_as_host' bug. memcpy: detected …

May 19, 2024
CVE-2024-35943
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: ti: Add a null pointer check to the omap_prm_domain_init devm_kasprintf() returns a pointer to …

May 19, 2024
CVE-2024-35942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: imx8mp_blk: Add fdcc clock to hdmimix domain According to i.MX8MP RM and HDMI …

May 19, 2024
CVE-2024-35941

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 19, 2024
CVE-2024-35940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pstore/zone: Add a null pointer check to the psz_kmsg_read kasprintf() returns a pointer to dynamically …

May 19, 2024
CVE-2024-35939
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure On TDX it is possible for the untrusted host …

May 19, 2024
CVE-2024-35938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: decrease MHI channel buffer length to 8KB Currently buf_len field of ath11k_mhi_config_qca6390 is …

May 19, 2024
CVE-2024-35937
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in …

May 19, 2024
CVE-2024-35936
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle chunk tree lookup error in btrfs_relocate_sys_chunks() The unhandled case in btrfs_relocate_sys_chunks() loop is …

May 19, 2024
CVE-2024-35935
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref underflow in header iterate_inode_ref() Change BUG_ON to proper error handling …

May 19, 2024
CVE-2024-35934
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: reduce rtnl pressure in smc_pnet_create_pnetids_list() Many syzbot reports show extreme rtnl pressure, and many …

May 19, 2024
CVE-2024-35933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Fix null ptr deref in btintel_read_version If hci_cmd_sync_complete() is triggered and skb is …

May 19, 2024
CVE-2024-35932
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: don't check if plane->state->fb == state->fb Currently, when using non-blocking commits, we can see …

May 19, 2024
CVE-2024-35931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Skip do PCI error slot reset during RAS recovery Why: The PCI error slot …

May 19, 2024
CVE-2024-35930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix possible memory leak in lpfc_rcv_padisc() The call to lpfc_sli4_resume_rpi() in lpfc_rcv_padisc() may …

May 19, 2024
CVE-2024-35929
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix WARN_ON_ONCE() in the rcu_nocb_bypass_lock() For the kernels built with CONFIG_RCU_NOCB_CPU_DEFAULT_ALL=y and CONFIG_RCU_LAZY=y, the …

May 19, 2024
CVE-2024-35928

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 19, 2024
CVE-2024-35927
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm: Check output polling initialized before disabling In drm_kms_helper_poll_disable() check if output polling support is …

May 19, 2024
CVE-2024-35926
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix async_disable descriptor leak The disable_async paths of iaa_compress/decompress() don't free idxd …

May 19, 2024
CVE-2024-35925
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: prevent division by zero in blk_rq_stat_sum() The expression dst->nr_samples + src->nr_samples may have zero …

May 19, 2024
CVE-2024-35924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Limit read size on v1.2 Between UCSI 1.2 and UCSI 2.0, the …

May 19, 2024
CVE-2024-35923

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 19, 2024
CVE-2024-35922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbmon: prevent division by zero in fb_videomode_from_videomode() The expression htotal * vtotal can have a …

May 19, 2024
CVE-2024-35921
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix oops when HEVC init fails The stateless HEVC decoder saves the …

May 19, 2024
CVE-2024-35920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect decoder context list Add a lock for the …

May 19, 2024
CVE-2024-35919
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect encoder context list Add a lock for the …

May 19, 2024
CVE-2024-35918

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 19, 2024
CVE-2023-52699
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in …

May 19, 2024
CVE-2024-35917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_plt pointer arithmetic Kui-Feng Lee reported a crash on s390x triggered by the …

May 19, 2024
CVE-2024-35916
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dma-buf: Fix NULL pointer dereference in sanitycheck() If due to a memory allocation failure mock_chain() …

May 19, 2024
CVE-2024-35915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet syzbot reported the following uninit-value access issue …

May 19, 2024
CVE-2024-35914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix error cleanup path in nfsd_rename() Commit a8b0026847b8 ("rename(): avoid a deadlock in the …

May 19, 2024
CVE-2024-35913
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pick the version of SESSION_PROTECTION_NOTIF When we want to know whether we …

May 19, 2024
CVE-2024-35912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: rfi: fix potential response leaks If the rx payload length check fails, …

May 19, 2024
CVE-2024-35911
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ice: fix memory corruption bug with suspend and rebuild The ice driver would previously panic …

May 19, 2024
CVE-2024-35910
5.8 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp: properly terminate timers for kernel sockets We had various syzbot reports about tcp timers …

May 19, 2024
CVE-2024-35909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Split 64bit accesses to fix alignment issues Some of the registers are …

May 19, 2024
CVE-2024-35908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tls: get psock ref after taking rxlock to avoid leak At the start of tls_sw_recvmsg, …

May 19, 2024
CVE-2024-35907
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mlxbf_gige: call request_irq() after NAPI initialized The mlxbf_gige driver encounters a NULL pointer exception in …

May 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.