CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-28952
5.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.

May 3, 2024
CVE-2022-48705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921e: fix crash in chip reset fail In case of drv own fail …

May 3, 2024
CVE-2022-48704
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence and …

May 3, 2024
CVE-2022-48690
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: Fix DMA mappings leak Fix leak, when user changes ring parameters. During reallocation of …

May 3, 2024
CVE-2021-20556
5.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force …

May 3, 2024
CVE-2024-33793
5.3 MEDIUM

netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.

May 3, 2024
CVE-2024-33791
4.6 MEDIUM

A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

May 3, 2024
CVE-2024-30851
6.5 MEDIUM

Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.php component.

May 3, 2024
CVE-2021-20450
4.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get …

May 3, 2024
CVE-2020-4874
5.9 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

May 3, 2024
CVE-2024-34449
6.1 MEDIUM

Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

May 3, 2024
CVE-2022-48703
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a …

May 3, 2024
CVE-2022-48699
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/debug: fix dentry leak in update_sched_domain_debugfs Kuyo reports that the pattern of using debugfs_remove(debugfs_lookup()) leaks …

May 3, 2024
CVE-2022-48698
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix memory leak when using debugfs_lookup() When calling debugfs_lookup() the result must have dput() …

May 3, 2024
CVE-2022-48697
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a use-after-free Fix the following use-after-free complaint triggered by blktests nvme/004: BUG: KASAN: …

May 3, 2024
CVE-2022-48696
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: regmap: spi: Reserve space for register address/padding Currently the max_raw_read and max_raw_write limits in regmap_spi …

May 3, 2024
CVE-2022-48693
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: brcmstb: pm-arm: Fix refcount leak and __iomem leak bugs In brcmstb_pm_probe(), there are two …

May 3, 2024
CVE-2022-48692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Set scmnd->result only when scmnd is not NULL This change fixes the following kernel …

May 3, 2024
CVE-2022-48691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clean up hook list when offload flags check fails splice back the hook …

May 3, 2024
CVE-2022-48688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix kernel crash during module removal The driver incorrectly frees client instance and subsequent …

May 3, 2024
CVE-2022-48687
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix out-of-bounds read when setting HMAC data. The SRv6 layer allows defining HMAC …

May 3, 2024
CVE-2022-48675
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix a nested dead lock as part of ODP flow Fix a nested dead …

May 3, 2024
CVE-2022-48673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in link clear After modifying the QP to …

May 3, 2024
CVE-2022-48671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cgroup: Add missing cpus_read_lock() to cgroup_attach_task_all() syzbot is hitting percpu_rwsem_assert_held(&cpu_hotplug_lock) warning at cpuset_attach() [1], for …

May 3, 2024
CVE-2024-3109
6.3 MEDIUM

A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker …

May 3, 2024
CVE-2024-3108
5.5 MEDIUM

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device …

May 3, 2024
CVE-2024-1395
6.7 MEDIUM

Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing …

May 3, 2024
CVE-2023-6363
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

May 3, 2024
CVE-2023-41830
6.5 MEDIUM

An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.

May 3, 2024
CVE-2023-41828
4.4 MEDIUM

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.

May 3, 2024
CVE-2023-41826
5.1 MEDIUM

A PendingIntent hijacking vulnerability in Motorola Device Help (Genie) application that could allow local attackers to access files or interact with non-exported software components without …

May 3, 2024
CVE-2023-41823
4.4 MEDIUM

An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.

May 3, 2024
CVE-2023-41822
4.8 MEDIUM

An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.

May 3, 2024
CVE-2023-41821
5.0 MEDIUM

A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.

May 3, 2024
CVE-2023-41820
5.0 MEDIUM

An implicit intent vulnerability was reported in the Motorola Ready For application that could allow a local attacker to read information about connected Bluetooth audio …

May 3, 2024
CVE-2023-41819
6.1 MEDIUM

A PendingIntent hijacking vulnerability was reported in the Motorola Face Unlock application that could allow a local attacker to access unauthorized content providers.

May 3, 2024
CVE-2023-41818
5.0 MEDIUM

An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker …

May 3, 2024
CVE-2023-41816
5.0 MEDIUM

An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.

May 3, 2024
CVE-2024-34062
4.8 MEDIUM

tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, …

May 3, 2024
CVE-2024-33937
4.3 MEDIUM

Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13.

May 3, 2024
CVE-2024-33931
6.5 MEDIUM

Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.

May 3, 2024
CVE-2024-33929
5.3 MEDIUM

Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6.

May 3, 2024
CVE-2024-33925
4.3 MEDIUM

Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

May 3, 2024
CVE-2024-33923
6.3 MEDIUM

Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69.

May 3, 2024
CVE-2024-33921
4.3 MEDIUM

Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21.

May 3, 2024
CVE-2024-33920
5.3 MEDIUM

Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3.

May 3, 2024
CVE-2024-33919
6.5 MEDIUM

Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1.

May 3, 2024
CVE-2024-33915
4.3 MEDIUM

Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.

May 3, 2024
CVE-2024-33914
4.3 MEDIUM

Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.

May 3, 2024
CVE-2024-23914
5.7 MEDIUM

Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM …

May 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.