CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1847
7.8 HIGH

Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in …

Feb 28, 2024
CVE-2024-27515
7.2 HIGH

Osclass 5.1.2 is vulnerable to SQL Injection.

Feb 28, 2024
CVE-2024-25902
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.

Feb 28, 2024
CVE-2024-24868
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & …

Feb 28, 2024
CVE-2024-21886
7.8 HIGH

A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in …

Feb 28, 2024
CVE-2024-21885
7.8 HIGH

A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs …

Feb 28, 2024
CVE-2024-1636
8.0 HIGH

Potential Cross-Site Scripting (XSS) in the page editing area.

Feb 28, 2024
CVE-2024-1632
8.8 HIGH

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

Feb 28, 2024
CVE-2024-0786
8.8 HIGH

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL …

Feb 28, 2024
CVE-2021-47049
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Use after free in __vmbus_open() The "open_info" variable is added to the …

Feb 28, 2024
CVE-2021-47048
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op When handling op->addr, it is using the buffer "tmpbuf" …

Feb 28, 2024
CVE-2021-47046
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix off by one in hdmi_14_process_transaction() The hdcp_i2c_offsets[] array did not have an entry …

Feb 28, 2024
CVE-2021-47044
7.7 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix shift-out-of-bounds in load_balance() Syzbot reported a handful of occurrences where an sd->nr_balance_failed can …

Feb 28, 2024
CVE-2021-47040
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix overflows checks in provide buffers Colin reported before possible overflow and sign extension …

Feb 28, 2024
CVE-2021-47039
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ataflop: potential out of bounds in do_format() The function uses "type" as an array index: …

Feb 28, 2024
CVE-2021-47028
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7915: fix txrate reporting Properly check rate_info to fix unexpected reporting. [ 1215.161863] Call …

Feb 28, 2024
CVE-2021-47026
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-clt: destroy sysfs after removing session from active list A session can be removed dynamically …

Feb 28, 2024
CVE-2021-47025
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Always enable the clk on resume In mtk_iommu_runtime_resume always enable the clk, even if …

Feb 28, 2024
CVE-2021-47023
8.2 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on init For some reason there might be …

Feb 28, 2024
CVE-2021-47017
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ath10k: Fix a use after free in ath10k_htc_send_bundle In ath10k_htc_send_bundle, the bundle_skb could be freed …

Feb 28, 2024
CVE-2021-47014
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's …

Feb 28, 2024
CVE-2021-47013
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some …

Feb 28, 2024
CVE-2021-47012
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix a use after free in siw_alloc_mr Our code analyzer reported a UAF. In …

Feb 28, 2024
CVE-2021-47010
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: Only allow init netns to set default tcp cong to a restricted algo tcp_set_default_congestion_control() …

Feb 28, 2024
CVE-2021-47004
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid touching checkpointed data in get_victim() In CP disabling mode, there are …

Feb 28, 2024
CVE-2021-46999
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few …

Feb 28, 2024
CVE-2021-46998
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ethernet:enic: Fix a use after free bug in enic_hard_start_xmit In enic_hard_start_xmit, it calls enic_queue_wq_skb(). Inside …

Feb 28, 2024
CVE-2021-46993
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched: Fix out-of-bound access in uclamp Util-clamp places tasks in different buckets based on their …

Feb 28, 2024
CVE-2021-46992
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: avoid overflows in nft_hash_buckets() Number of buckets being stored in 32bit variables, we …

Feb 28, 2024
CVE-2021-46991
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix use-after-free in i40e_client_subtask() Currently the call to i40e_client_del_instance frees the object pf->cinst, however …

Feb 28, 2024
CVE-2021-46984
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: kyber: fix out of bounds access when preempted __blk_mq_sched_bio_merge() gets the ctx and hctx for …

Feb 28, 2024
CVE-2021-46980
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Retrieve all the PDOs instead of just the first 4 commit 4dbc6a4ef06d …

Feb 28, 2024
CVE-2021-46978
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Always make an attempt to map eVMCS after migration When enlightened VMCS is …

Feb 28, 2024
CVE-2020-36785
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all …

Feb 28, 2024
CVE-2024-26298
7.2 HIGH

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could …

Feb 27, 2024
CVE-2024-26297
7.2 HIGH

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could …

Feb 27, 2024
CVE-2024-26296
7.2 HIGH

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could …

Feb 27, 2024
CVE-2024-26295
7.2 HIGH

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could …

Feb 27, 2024
CVE-2024-26294
7.2 HIGH

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could …

Feb 27, 2024
CVE-2024-0763
8.1 HIGH

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need …

Feb 27, 2024
CVE-2024-24027
7.2 HIGH

SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansLists.

Feb 27, 2024
CVE-2021-46973
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Avoid potential use after free in MHI send It is possible that the …

Feb 27, 2024
CVE-2021-46969
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Fix invalid error returning in mhi_queue mhi_queue returns an error when the …

Feb 27, 2024
CVE-2021-46966
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ACPI: custom_method: fix potential use-after-free issue In cm_write(), buf is always freed when reaching the …

Feb 27, 2024
CVE-2021-46965
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: physmap: physmap-bt1-rom: Fix unintentional stack access Cast &data to (char *) in order to …

Feb 27, 2024
CVE-2021-46955
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with …

Feb 27, 2024
CVE-2021-46954
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_frag: fix stack OOB read while fragmenting IPv4 packets when 'act_mirred' tries to fragment …

Feb 27, 2024
CVE-2021-46952
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFS: fs_context: validate UDP retrans to prevent shift out-of-bounds Fix shift out-of-bounds in xprt_calc_majortimeo(). This …

Feb 27, 2024
CVE-2021-46950
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: md/raid1: properly indicate failure when ending a failed write request This patch addresses a data …

Feb 27, 2024
CVE-2021-46943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: staging/intel-ipu3: Fix set_fmt error handling If there in an error during a set_fmt, do …

Feb 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.