CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8033
4.3 MEDIUM

Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker who convinced a user to install a malicious application …

Aug 21, 2024
CVE-2024-7981
4.3 MEDIUM

Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 21, 2024
CVE-2024-7978
4.3 MEDIUM

Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 21, 2024
CVE-2024-7976
4.3 MEDIUM

Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 21, 2024
CVE-2024-7975
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 21, 2024
CVE-2024-20486
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery …

Aug 21, 2024
CVE-2024-20466
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an …

Aug 21, 2024
CVE-2024-20417
6.5 MEDIUM

Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These …

Aug 21, 2024
CVE-2024-41572
6.1 MEDIUM

Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in …

Aug 21, 2024
CVE-2024-20488
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …

Aug 21, 2024
CVE-2024-42550
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts …

Aug 21, 2024
CVE-2024-7722
4.3 MEDIUM

Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

Aug 21, 2024
CVE-2024-7602
6.5 MEDIUM

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps …

Aug 21, 2024
CVE-2024-41937
6.1 MEDIUM

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on …

Aug 21, 2024
CVE-2024-43407
6.1 MEDIUM

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a …

Aug 21, 2024
CVE-2024-43371
4.5 MEDIUM

CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource …

Aug 21, 2024
CVE-2024-41675
6.8 MEDIUM

CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming …

Aug 21, 2024
CVE-2024-41674
5.3 MEDIUM

CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal …

Aug 21, 2024
CVE-2024-6339
6.1 MEDIUM

The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions up to, and including, 5.16.4 due to …

Aug 21, 2024
CVE-2023-52914
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: add hash if ready poll request can't complete inline If we don't, then we …

Aug 21, 2024
CVE-2023-52913
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential context UAFs gem_context_register() makes the context visible to userspace, and which point …

Aug 21, 2024
CVE-2023-52912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fixed bug on error when unloading amdgpu Fixed bug on error when unloading amdgpu. …

Aug 21, 2024
CVE-2023-52911
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm: another fix for the headless Adreno GPU Fix another oops reproducible when rebooting the …

Aug 21, 2024
CVE-2023-52910
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/iova: Fix alloc iova overflows issue In __alloc_and_insert_iova_range, there is an issue that retry_pfn overflows. …

Aug 21, 2024
CVE-2023-52909
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix handling of cached open files in nfsd4_open codepath Commit fb70bf124b05 ("NFSD: Instantiate a …

Aug 21, 2024
CVE-2023-52908
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix potential NULL dereference Fix potential NULL dereference, in the case when "man", the …

Aug 21, 2024
CVE-2023-52907
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Wait for out_urb's completion in pn533_usb_send_frame() Fix a use-after-free that occurs in hcd …

Aug 21, 2024
CVE-2023-52905
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix resource leakage in VF driver unbind resources allocated like mcam entries to support …

Aug 21, 2024
CVE-2023-52904
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix possible NULL pointer dereference in snd_usb_pcm_has_fixed_rate() The subs function argument may be …

Aug 21, 2024
CVE-2023-52903
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: lock overflowing for IOPOLL syzbot reports an issue with overflow filling for IOPOLL: WARNING: …

Aug 21, 2024
CVE-2023-52902
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nommu: fix memory leak in do_mmap() error path The preallocation of the maple tree nodes …

Aug 21, 2024
CVE-2023-52901
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check endpoint is valid before dereferencing it When the host controller is not …

Aug 21, 2024
CVE-2023-52900
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix general protection fault in nilfs_btree_insert() If nilfs2 reads a corrupted disk image and …

Aug 21, 2024
CVE-2023-52899
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Add exception protection processing for vd in axi_chan_handle_err function Since there is no protection for …

Aug 21, 2024
CVE-2023-52898
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xhci: Fix null pointer dereference when host dies Make sure xhci_free_dev() and xhci_kill_endpoint_urbs() do not …

Aug 21, 2024
CVE-2023-52897
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: do not warn on record without old_roots populated [BUG] There are some reports …

Aug 21, 2024
CVE-2023-52896
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race between quota rescan and disable leading to NULL pointer deref If we …

Aug 21, 2024
CVE-2023-52895
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: don't reissue in case of poll race on multishot request A previous commit fixed …

Aug 21, 2024
CVE-2023-52894
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate() In Google internal bug 265639009 …

Aug 21, 2024
CVE-2023-52893
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gsmi: fix null-deref in gsmi_get_variable We can get EFI variables without fetching the attribute, so …

Aug 21, 2024
CVE-2022-48899
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix GEM handle creation UAF Userspace can guess the handle value and try to …

Aug 21, 2024
CVE-2022-48898
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: do not complete dp_aux_cmd_fifo_tx() if irq is not for aux transfer There are 3 …

Aug 21, 2024
CVE-2022-48897
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64/mm: fix incorrect file_map_count for invalid pmd The page table check trigger BUG_ON() unexpectedly when …

Aug 21, 2024
CVE-2022-48896
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix pci device refcount leak As the comment of pci_get_domain_bus_and_slot() says, it returns a …

Aug 21, 2024
CVE-2022-48895
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu: Don't unregister on shutdown Michael Walle says he noticed the following stack trace while …

Aug 21, 2024
CVE-2022-48894
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Don't unregister on shutdown Similar to SMMUv2, this driver calls iommu_device_unregister() from the shutdown …

Aug 21, 2024
CVE-2022-48893
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Cleanup partial engine discovery failures If we abort driver initialisation in the middle of …

Aug 21, 2024
CVE-2022-48891
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regulator: da9211: Use irq handler when ready If the system does not come from reset …

Aug 21, 2024
CVE-2022-48890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM storvsc_queuecommand() maps the scatter/gather list …

Aug 21, 2024
CVE-2022-48889
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof-nau8825: fix module alias overflow The maximum name length for a platform_device_id entry …

Aug 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.