53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
In the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9834: Validate frequency parameter value In ad9834_write_frequency() clk_get_rate() can return 0. In …
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection [Why] These registers should not be read …
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid overflow from uint32_t to uint8_t [WHAT & HOW] dmub_rb_cmd's ramping_boundary has size of …
In the Linux kernel, the following vulnerability has been resolved: fsnotify: clear PARENT_WATCHED flags lazily In some setups directories can have many (usually negative) dentries. …
In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt mode produce …
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable DMCUB timeout for DCN35 [Why] DMCUB can intermittently take longer than expected to …
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …
Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …
Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …
Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …
The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and …
The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due …
In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution …
In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege …
An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is …
An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it …
An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because …
OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) …
The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, …
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via …
Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed …
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
Power BI Report Server Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
Outlook for Android Elevation of Privilege Vulnerability
Visual Studio Collector Service Denial of Service Vulnerability
Code Integrity Guard Security Feature Bypass Vulnerability
Windows MSHTML Platform Spoofing Vulnerability
Sudo for Windows Spoofing Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kerberos Information Disclosure Vulnerability
Windows Cryptographic Information Disclosure Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Denial of Service Vulnerability
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Free website and port scanning — find vulnerabilities before attackers do.