CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46695
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user …

Sep 13, 2024
CVE-2024-46694
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from …

Sep 13, 2024
CVE-2024-46693
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink: Fix race during initialization As pointed out by Stephen Boyd it is …

Sep 13, 2024
CVE-2024-46692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Mark get_wq_ctx() as atomic call Currently get_wq_ctx() is wrongly configured as a …

Sep 13, 2024
CVE-2024-46691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Move unregister out of atomic section Commit '9329933699b3 ("soc: qcom: pmic_glink: Make …

Sep 13, 2024
CVE-2024-46690
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd4_deleg_getattr_conflict in presence of third party lease It is not safe to dereference …

Sep 13, 2024
CVE-2024-46689
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: cmd-db: Map shared memory as WC, not WB Linux does not write into …

Sep 13, 2024
CVE-2024-46688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs: fix out-of-bound access when z_erofs_gbuf_growsize() partially fails If z_erofs_gbuf_growsize() partially fails on a global …

Sep 13, 2024
CVE-2024-46686
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req() This happens when called from SMB2_read() while using rdma …

Sep 13, 2024
CVE-2024-46685
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: single: fix potential NULL dereference in pcs_get_function() pinmux_generic_get_function() can return NULL and the pointer …

Sep 13, 2024
CVE-2024-46684
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binfmt_elf_fdpic: fix AUXV size calculation when ELF_HWCAP2 is defined create_elf_fdpic_tables() does not correctly account the …

Sep 13, 2024
CVE-2024-46682
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: prevent panic for nfsv4.0 closed files in nfs4_show_open Prior to commit 3f29cc82a84c ("nfsd: split …

Sep 13, 2024
CVE-2024-46681
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pktgen: use cpus_read_lock() in pg_net_init() I have seen the WARN_ON(smp_processor_id() != cpu) firing in pktgen_thread_worker() …

Sep 13, 2024
CVE-2024-46680
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix random crash seen while removing driver This fixes the random kernel crash …

Sep 13, 2024
CVE-2024-46679
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ethtool: check device is present when getting link settings A sysfs reader can race with …

Sep 13, 2024
CVE-2024-46678
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond->ipsec_lock is added …

Sep 13, 2024
CVE-2024-46677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gtp: fix a potential NULL pointer dereference When sockfd_lookup() fails, gtp_encap_enable_socket() returns a NULL pointer, …

Sep 13, 2024
CVE-2024-46676
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Add poll mod list filling check In case of im_protocols value is 1 …

Sep 13, 2024
CVE-2024-46675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: core: Prevent USB core invalid event buffer address access This commit addresses an …

Sep 13, 2024
CVE-2024-8656
6.1 MEDIUM

The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Sep 13, 2024
CVE-2024-43180
4.3 MEDIUM

IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by …

Sep 13, 2024
CVE-2024-8762
6.3 MEDIUM

A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatedata.php. …

Sep 13, 2024
CVE-2024-45607
5.8 MEDIUM

whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the …

Sep 12, 2024
CVE-2024-8641
6.7 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 …

Sep 12, 2024
CVE-2024-8311
6.5 MEDIUM

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows …

Sep 12, 2024
CVE-2024-4472
4.0 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from …

Sep 12, 2024
CVE-2024-45383
5.0 MEDIUM

A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can …

Sep 12, 2024
CVE-2024-45303
6.1 MEDIUM

Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be …

Sep 12, 2024
CVE-2024-45182
5.5 MEDIUM

An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause …

Sep 12, 2024
CVE-2024-34336
5.3 MEDIUM

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of …

Sep 12, 2024
CVE-2024-34335
6.1 MEDIUM

ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.

Sep 12, 2024
CVE-2024-25270
4.3 MEDIUM

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment …

Sep 12, 2024
CVE-2024-41629
5.5 MEDIUM

An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials

Sep 12, 2024
CVE-2020-24061
4.3 MEDIUM

Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies …

Sep 12, 2024
CVE-2024-8754
6.4 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. …

Sep 12, 2024
CVE-2024-8631
5.5 MEDIUM

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and …

Sep 12, 2024
CVE-2024-6840
6.6 MEDIUM

An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request …

Sep 12, 2024
CVE-2024-6389
4.3 MEDIUM

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a …

Sep 12, 2024
CVE-2024-5435
4.5 MEDIUM

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all …

Sep 12, 2024
CVE-2024-4660
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions …

Sep 12, 2024
CVE-2024-4612
6.4 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain …

Sep 12, 2024
CVE-2024-2743
5.3 MEDIUM

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to …

Sep 12, 2024
CVE-2024-6702
5.2 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

Sep 12, 2024
CVE-2024-6701
5.5 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.

Sep 12, 2024
CVE-2024-6700
5.5 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.

Sep 12, 2024
CVE-2024-45826
6.8 MEDIUM

CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If …

Sep 12, 2024
CVE-2024-42484
6.5 MEDIUM

ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there …

Sep 12, 2024
CVE-2024-42483
6.5 MEDIUM

ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not …

Sep 12, 2024
CVE-2024-28990
6.3 MEDIUM

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ …

Sep 12, 2024
CVE-2022-26322
4.9 MEDIUM

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before …

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.