CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55627
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead …

Jan 6, 2025
CVE-2024-46073
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, …

Jan 6, 2025
CVE-2025-21615
5.5 MEDIUM

AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to …

Jan 6, 2025
CVE-2024-56769
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg Syzbot reports [1] an uninitialized value issue found …

Jan 6, 2025
CVE-2024-56768
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP On x86-64 calling bpf_get_smp_processor_id() in a kernel with CONFIG_SMP disabled …

Jan 6, 2025
CVE-2024-56767
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset The at_xdmac_memset_create_desc may return NULL, which will lead to …

Jan 6, 2025
CVE-2024-56763
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_write If a large count is provided, it will trigger …

Jan 6, 2025
CVE-2024-56761
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fred: Clear WFE in missing-ENDBRANCH #CPs An indirect branch instruction sets the CPU indirect branch …

Jan 6, 2025
CVE-2024-56760
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Handle lack of irqdomain gracefully Alexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a …

Jan 6, 2025
CVE-2024-56758
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: check folio mapping after unlock in relocate_one_folio() When we call btrfs_read_folio() to bring a …

Jan 6, 2025
CVE-2024-56757
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb …

Jan 6, 2025
CVE-2024-47475
5.0 MEDIUM

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading …

Jan 6, 2025
CVE-2023-6604
5.3 MEDIUM

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service …

Jan 6, 2025
CVE-2023-6601
4.7 MEDIUM

A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended …

Jan 6, 2025
CVE-2024-51112
6.1 MEDIUM

Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script

Jan 6, 2025
CVE-2024-51111
4.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of …

Jan 6, 2025
CVE-2024-31914
6.4 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed …

Jan 6, 2025
CVE-2024-31913
5.5 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed …

Jan 6, 2025
CVE-2024-45559
5.5 MEDIUM

Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.

Jan 6, 2025
CVE-2024-43063
6.1 MEDIUM

information disclosure while invoking the mailbox read API.

Jan 6, 2025
CVE-2024-33067
6.1 MEDIUM

Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

Jan 6, 2025
CVE-2024-33061
6.8 MEDIUM

Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.

Jan 6, 2025
CVE-2024-33059
6.7 MEDIUM

Memory corruption while processing frame command IOCTL calls.

Jan 6, 2025
CVE-2024-33055
6.7 MEDIUM

Memory corruption while invoking IOCTL calls to unmap the DMA buffers.

Jan 6, 2025
CVE-2024-33041
6.7 MEDIUM

Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,

Jan 6, 2025
CVE-2024-23366
6.6 MEDIUM

Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.

Jan 6, 2025
CVE-2024-12311
6.5 MEDIUM

The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing …

Jan 6, 2025
CVE-2024-12302
6.1 MEDIUM

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform …

Jan 6, 2025
CVE-2024-11849
6.1 MEDIUM

The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 6, 2025
CVE-2024-11356
6.1 MEDIUM

The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to …

Jan 6, 2025
CVE-2024-20152
4.4 MEDIUM

In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a …

Jan 6, 2025
CVE-2024-20151
6.7 MEDIUM

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if …

Jan 6, 2025
CVE-2024-20145
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Jan 6, 2025
CVE-2024-20144
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Jan 6, 2025
CVE-2024-20143
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Jan 6, 2025
CVE-2024-20140
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Jan 6, 2025
CVE-2024-20105
6.7 MEDIUM

In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Jan 6, 2025
CVE-2024-13145
6.3 MEDIUM

A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uploadController. java. The …

Jan 6, 2025
CVE-2024-13144
6.3 MEDIUM

A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the …

Jan 6, 2025
CVE-2025-0232
6.3 MEDIUM

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 5, 2025
CVE-2025-0231
6.3 MEDIUM

A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jan 5, 2025
CVE-2025-0230
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file /admin/print.php. The …

Jan 5, 2025
CVE-2025-0229
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This issue affects some unknown processing of the file …

Jan 5, 2025
CVE-2025-0227
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. …

Jan 5, 2025
CVE-2025-0226
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download …

Jan 5, 2025
CVE-2025-0225
4.3 MEDIUM

A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file …

Jan 5, 2025
CVE-2025-0224
5.3 MEDIUM

A vulnerability was found in Provision-ISR SH-4050A-2, SH-4100A-2L(MM), SH-8100A-2L(MM), SH-16200A-2(1U), SH-16200A-5(1U) and NVR5-8200PX up to 20241220. It has been declared as problematic. Affected by this …

Jan 5, 2025
CVE-2025-0223
5.5 MEDIUM

A vulnerability was found in IObit Protected Folder up to 13.6.0.5. It has been classified as problematic. Affected is the function 0x8001E000/0x8001E00C/0x8001E004/0x8001E010 in the library …

Jan 5, 2025
CVE-2025-0222
5.5 MEDIUM

A vulnerability was found in IObit Protected Folder up to 13.6.0.5 and classified as problematic. This issue affects the function 0x8001E000/0x8001E004 in the library IUProcessFilter.sys …

Jan 5, 2025
CVE-2025-0221
5.5 MEDIUM

A vulnerability has been found in IOBit Protected Folder up to 1.3.0 and classified as problematic. This vulnerability affects the function 0x22200c in the library …

Jan 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.