CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31997
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and …

Apr 10, 2024
CVE-2024-31995
4.3 MEDIUM

`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is …

Apr 10, 2024
CVE-2024-29504
7.6 HIGH

Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.

Apr 10, 2024
CVE-2024-31996
10.0 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool …

Apr 10, 2024
CVE-2024-31988
9.6 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed …

Apr 10, 2024
CVE-2024-31987
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any …

Apr 10, 2024
CVE-2024-31986
9.0 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a …

Apr 10, 2024
CVE-2024-31985
5.4 MEDIUM

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing …

Apr 10, 2024
CVE-2024-29460
6.6 MEDIUM

An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location …

Apr 10, 2024
CVE-2024-26362
8.8 HIGH

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted …

Apr 10, 2024
CVE-2024-1481
5.3 MEDIUM

A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as …

Apr 10, 2024
CVE-2024-31984
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a …

Apr 10, 2024
CVE-2024-31983
9.9 CRITICAL

XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that …

Apr 10, 2024
CVE-2024-31982
10.0 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code …

Apr 10, 2024
CVE-2024-31981
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via …

Apr 10, 2024
CVE-2024-31939
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Import any XML or CSV File to WordPress: …

Apr 10, 2024
CVE-2024-31819
9.8 CRITICAL

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

Apr 10, 2024
CVE-2024-31465
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on …

Apr 10, 2024
CVE-2024-31430
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional …

Apr 10, 2024
CVE-2024-29502
6.5 MEDIUM

An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths.

Apr 10, 2024
CVE-2024-29500
9.8 CRITICAL

An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.

Apr 10, 2024
CVE-2024-29269
8.8 HIGH

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

Apr 10, 2024
CVE-2024-3516
6.5 MEDIUM

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 10, 2024
CVE-2024-3515
6.5 MEDIUM

Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 10, 2024
CVE-2024-3157
9.6 CRITICAL

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially …

Apr 10, 2024
CVE-2024-31464
6.8 MEDIUM

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the …

Apr 10, 2024
CVE-2024-31386
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, …

Apr 10, 2024
CVE-2024-28345
5.5 MEDIUM

An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.

Apr 10, 2024
CVE-2024-28344
3.1 LOW

An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in …

Apr 10, 2024
CVE-2024-23077
7.5 HIGH

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disputed by multiple third parties who believe there was …

Apr 10, 2024
CVE-2023-52070
8.4 HIGH

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who …

Apr 10, 2024
CVE-2021-47219
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs() The following issue was observed running syzkaller: BUG: …

Apr 10, 2024
CVE-2021-47218
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash table slot array allocation …

Apr 10, 2024
CVE-2021-47217
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/hyperv: Fix NULL deref in set_hv_tscchange_cb() if Hyper-V setup fails Check for a valid hv_vp_index …

Apr 10, 2024
CVE-2021-47216
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: advansys: Fix kernel pointer leak Pointers should be printed with %p or %px rather …

Apr 10, 2024
CVE-2021-47215
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix crash in RX resync flow For the TLS RX resync flow, we …

Apr 10, 2024
CVE-2021-47214
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hugetlb, userfaultfd: fix reservation restore on userfaultfd error Currently in the is_continue case in hugetlb_mcopy_atomic_pte(), …

Apr 10, 2024
CVE-2021-47213

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 10, 2024
CVE-2021-47212
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Update error handler for UCTX and UMEM In the fast unload flow, the device …

Apr 10, 2024
CVE-2021-47211
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix null pointer dereference on pointer cs_desc The pointer cs_desc return from snd_usb_find_clock_source …

Apr 10, 2024
CVE-2021-47210
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Calling tps6598x_block_read with a higher than allowed len …

Apr 10, 2024
CVE-2021-47209
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Prevent dead task groups from regaining cfs_rq's Kevin is reporting crashes which point to …

Apr 10, 2024
CVE-2021-47207
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: gus: fix null pointer dereference on pointer block The pointer block return from snd_gf1_dma_next_block …

Apr 10, 2024
CVE-2021-47206
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: host: ohci-tmio: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() …

Apr 10, 2024
CVE-2021-47205
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: Unregister clocks/resets when unbinding Currently, unbinding a CCU driver unmaps the device's MMIO …

Apr 10, 2024
CVE-2021-47204
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: dpaa2-eth: fix use-after-free in dpaa2_eth_remove Access to netdev after free_netdev() will cause use-after-free bug. …

Apr 10, 2024
CVE-2021-47203
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() When parsing the txq list in lpfc_drain_txq(), the …

Apr 10, 2024
CVE-2021-47202
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_zones() parses the thermal-zones node and registers …

Apr 10, 2024
CVE-2021-47201
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iavf: free q_vectors before queues in iavf_disable_vf iavf_free_queues() clears adapter->num_active_queues, which iavf_free_q_vectors() relies on, so …

Apr 10, 2024
CVE-2021-47200
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/prime: Fix use after free in mmap with drm_gem_ttm_mmap drm_gem_ttm_mmap() drops a reference to the …

Apr 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.