CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23586
5.3 MEDIUM

HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthenticated attacker could obtain old session information.

Sep 27, 2024
CVE-2024-9293
6.3 MEDIUM

A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php …

Sep 27, 2024
CVE-2024-47186
6.1 MEDIUM

Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. …

Sep 27, 2024
CVE-2024-46453
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a …

Sep 27, 2024
CVE-2024-6436
6.5 MEDIUM

An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to the server and …

Sep 27, 2024
CVE-2024-46257
6.3 MEDIUM

A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is …

Sep 27, 2024
CVE-2024-39364
6.3 MEDIUM

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow for restarting the operating system, rebooting the hardware, and …

Sep 27, 2024
CVE-2024-37187
5.7 MEDIUM

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

Sep 27, 2024
CVE-2024-34542
5.7 MEDIUM

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Sep 27, 2024
CVE-2024-25412
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email …

Sep 27, 2024
CVE-2024-25411
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username …

Sep 27, 2024
CVE-2024-9284
6.5 MEDIUM

A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 27, 2024
CVE-2024-38809
5.3 MEDIUM

Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed …

Sep 27, 2024
CVE-2024-47077
6.5 MEDIUM

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and …

Sep 27, 2024
CVE-2024-45745
5.0 MEDIUM

TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access …

Sep 27, 2024
CVE-2024-46470
6.1 MEDIUM

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

Sep 27, 2024
CVE-2024-46333
4.8 MEDIUM

An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Sep 27, 2024
CVE-2024-47184
6.1 MEDIUM

Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site …

Sep 27, 2024
CVE-2024-47182
4.8 MEDIUM

Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible …

Sep 27, 2024
CVE-2024-45863
5.3 MEDIUM

A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects …

Sep 27, 2024
CVE-2024-9282
4.3 MEDIUM

A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation …

Sep 27, 2024
CVE-2024-9281
4.3 MEDIUM

A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The …

Sep 27, 2024
CVE-2024-46868
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire() If the __qcuefi pointer is not set, then …

Sep 27, 2024
CVE-2024-46867
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: fix deadlock in show_meminfo() There is a real deadlock as well as sleeping in …

Sep 27, 2024
CVE-2024-46866
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: add missing bo locking in show_meminfo() bo_meminfo() wants to inspect bo state like tt …

Sep 27, 2024
CVE-2024-46864
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/hyperv: fix kexec crash due to VP assist page corruption commit 9636be85cc5b ("x86/hyperv: Fix hyperv_pcpu_input_arg …

Sep 27, 2024
CVE-2024-46863
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, …

Sep 27, 2024
CVE-2024-46862
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, …

Sep 27, 2024
CVE-2024-46861
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usbnet: ipheth: do not stop RX on failing RX callback RX callbacks can fail for …

Sep 27, 2024
CVE-2024-46860
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change When disabling wifi mt7921_ipv6_addr_change() is called …

Sep 27, 2024
CVE-2024-46857
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix bridge mode operations when there are no VFs Currently, trying to set the …

Sep 27, 2024
CVE-2024-46856
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: dp83822: Fix NULL pointer dereference on DP83825 devices The probe() function is only …

Sep 27, 2024
CVE-2024-46855
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: fix sk refcount leaks We must put 'sk' reference before returning.

Sep 27, 2024
CVE-2024-46851
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct() dc_state_destruct() nulls the resource context of the DC …

Sep 27, 2024
CVE-2024-46850
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct() dc_state_destruct() nulls the resource context of the DC …

Sep 27, 2024
CVE-2024-46848
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Limit the period on Haswell Running the ltp test cve-2015-3290 concurrently reports the following …

Sep 27, 2024
CVE-2024-46847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: vmalloc: ensure vmap_block is initialised before adding to queue Commit 8c61291fd850 ("mm: fix incorrect …

Sep 27, 2024
CVE-2024-46846
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: rockchip: Resolve unbalanced runtime PM / system PM handling Commit e882575efc77 ("spi: rockchip: Suspend …

Sep 27, 2024
CVE-2024-46843
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove SCSI host only if added If host tries to remove ufshcd …

Sep 27, 2024
CVE-2024-46842
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info The MBX_TIMEOUT return code is not handled in …

Sep 27, 2024
CVE-2024-46841
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc() We handle errors here properly, ENOMEM …

Sep 27, 2024
CVE-2024-46840
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: clean up our handling of refs == 0 in snapshot delete In reada we …

Sep 27, 2024
CVE-2024-46838
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: don't BUG_ON() if khugepaged yanks our page table Since khugepaged was changed to allow …

Sep 27, 2024
CVE-2024-46837
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Restrict high priorities on group_create We were allowing any users to create a high …

Sep 27, 2024
CVE-2024-46835
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix smatch static checker warning adev->gfx.imu.funcs could be NULL

Sep 27, 2024
CVE-2024-46834
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ethtool: fail closed if we can't get max channel used in indirection tables Commit 0d1b7d6c9274 …

Sep 27, 2024
CVE-2024-46832
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: MIPS: cevt-r4k: Don't call get_c0_compare_int if timer irq is installed This avoids warning: [ 0.118053] …

Sep 27, 2024
CVE-2024-46829
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Drop rt_mutex::wait_lock before scheduling rt_mutex_handle_deadlock() is called with rt_mutex::wait_lock held. In the good case …

Sep 27, 2024
CVE-2024-46827
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix firmware crash due to invalid peer nss Currently, if the access point …

Sep 27, 2024
CVE-2024-46826
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ELF: fix kernel.randomize_va_space double read ELF loader uses "randomize_va_space" twice. It is sysctl and can …

Sep 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.