CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35151
6.5 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

Aug 22, 2024
CVE-2024-7778
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Aug 22, 2024
CVE-2024-6870
6.4 MEDIUM

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 …

Aug 22, 2024
CVE-2024-8072
5.3 MEDIUM

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

Aug 22, 2024
CVE-2024-8071
4.7 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as …

Aug 22, 2024
CVE-2024-43813
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel …

Aug 22, 2024
CVE-2024-42411
5.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a …

Aug 22, 2024
CVE-2024-40886
4.6 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used …

Aug 22, 2024
CVE-2024-39836
4.8 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or …

Aug 22, 2024
CVE-2024-39810
4.9 MEDIUM

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which …

Aug 22, 2024
CVE-2024-32939
4.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original …

Aug 22, 2024
CVE-2024-45165
5.3 MEDIUM

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the …

Aug 22, 2024
CVE-2022-48942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hwmon: Handle failure to register sensor with thermal zone correctly If an attempt is made …

Aug 22, 2024
CVE-2022-48941
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: fix concurrent reset and removal of VFs Commit c503e63200c6 ("ice: Stop processing VF messages …

Aug 22, 2024
CVE-2022-48940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix crash due to incorrect copy_map_value When both bpf_spin_lock and bpf_timer are present in …

Aug 22, 2024
CVE-2022-48938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like …

Aug 22, 2024
CVE-2022-48935
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unregister flowtable hooks on netns exit Unregister flowtable hooks before they are releases …

Aug 22, 2024
CVE-2022-48934
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac() ida_simple_get() returns an id between min (0) …

Aug 22, 2024
CVE-2022-48933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memory leak during stateful obj update stateful objects can be updated from …

Aug 22, 2024
CVE-2022-48932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, Fix slab-out-of-bounds in mlx5_cmd_dr_create_fte When adding a rule with 32 destinations, we hit …

Aug 22, 2024
CVE-2022-48931
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: configfs: fix a race in configfs_{,un}register_subsystem() When configfs_register_subsystem() or configfs_unregister_subsystem() is executing link_group() or unlink_group(), …

Aug 22, 2024
CVE-2022-48930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/ib_srp: Fix a deadlock Remove the flush_workqueue(system_long_wq) call since flushing system_long_wq is deadlock-prone and since …

Aug 22, 2024
CVE-2022-48929
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix crash due to out of bounds access into reg2btf_ids. When commit e6ac2450d6de ("bpf: …

Aug 22, 2024
CVE-2022-48928
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: men_z188_adc: Fix a resource leak in an error handling path If iio_device_register() fails, …

Aug 22, 2024
CVE-2024-7836
4.3 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, …

Aug 22, 2024
CVE-2024-5583
6.4 MEDIUM

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 22, 2024
CVE-2022-48924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: fix memory leak in int3400_notify() It is easy to hit the below memory …

Aug 22, 2024
CVE-2022-48923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: prevent copying too big compressed lzo segment Compressed length can be corrupted to be …

Aug 22, 2024
CVE-2022-48922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: fix oops caused by irqsoff latency tracer The trace_hardirqs_{on,off}() require the caller to setup …

Aug 22, 2024
CVE-2022-48921
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix fault in reweight_entity Syzbot found a GPF in reweight_entity. This has been bisected …

Aug 22, 2024
CVE-2022-48920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: get rid of warning on transaction commit when using flushoncommit When using the flushoncommit …

Aug 22, 2024
CVE-2022-48918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iwlwifi: mvm: check debugfs_dir ptr before use When "debugfs=off" is used on the kernel command …

Aug 22, 2024
CVE-2022-48916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix double list_add when enabling VMD in scalable mode When enabling VMD and IOMMU …

Aug 22, 2024
CVE-2022-48915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix TZ_GET_TRIP NULL pointer dereference Do not call get_trip_hyst() from thermal_genl_cmd_tz_get_trip() if the …

Aug 22, 2024
CVE-2022-48914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xen/netfront: destroy queues before real_num_tx_queues is zeroed xennet_destroy_queues() relies on info->netdev->real_num_tx_queues to delete queues. Since …

Aug 22, 2024
CVE-2022-48911
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: fix possible use-after-free Eric Dumazet says: The sock_hold() side seems suspect, because there …

Aug 22, 2024
CVE-2022-48910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ensure we call ipv6_mc_down() at most once There are two reasons for addrconf_notify() …

Aug 22, 2024
CVE-2022-48909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix connection leak There's a potential leak issue under following execution sequence : smc_release …

Aug 22, 2024
CVE-2022-48908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe() During driver initialization, the pointer of card info, …

Aug 22, 2024
CVE-2022-48907
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: auxdisplay: lcd2s: Fix memory leak in ->remove() Once allocated the struct lcd2s_data is never freed. …

Aug 22, 2024
CVE-2022-48906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: Correctly set DATA_FIN timeout when number of retransmits is large Syzkaller with UBSAN uncovered …

Aug 22, 2024
CVE-2022-48905
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: free reset-work-item when flushing Fix a tiny memory leak when flushing the reset work …

Aug 22, 2024
CVE-2022-48904
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix I/O page table memory leak The current logic updates the I/O page table …

Aug 22, 2024
CVE-2022-48903
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix relocation crash due to premature return from btrfs_commit_transaction() We are seeing crashes similar …

Aug 22, 2024
CVE-2022-48902
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not WARN_ON() if we have PageError set Whenever we do any extent buffer …

Aug 22, 2024
CVE-2022-48901
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not start relocation until in progress drops are done We hit a bug …

Aug 22, 2024
CVE-2021-4441
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynq-qspi: Fix a NULL pointer dereference in zynq_qspi_exec_mem_op() In zynq_qspi_exec_mem_op(), kzalloc() is directly used …

Aug 22, 2024
CVE-2024-42056
6.5 MEDIUM

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) …

Aug 22, 2024
CVE-2024-8035
4.3 MEDIUM

Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Aug 21, 2024
CVE-2024-8034
4.3 MEDIUM

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML …

Aug 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.