CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27908
4.9 MEDIUM

A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

Apr 5, 2024
CVE-2024-23592
6.3 MEDIUM

An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and …

Apr 5, 2024
CVE-2023-5912
6.7 MEDIUM

A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM …

Apr 5, 2024
CVE-2023-4605
6.5 MEDIUM

A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

Apr 5, 2024
CVE-2023-25494
6.7 MEDIUM

A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges …

Apr 5, 2024
CVE-2023-25493
6.7 MEDIUM

A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a …

Apr 5, 2024
CVE-2024-2312
6.7 MEDIUM

GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead …

Apr 5, 2024
CVE-2024-29783
6.7 MEDIUM

In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29782
5.5 MEDIUM

In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29755
4.4 MEDIUM

In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with …

Apr 5, 2024
CVE-2024-29754
6.2 MEDIUM

In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29751
5.5 MEDIUM

In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29750
5.5 MEDIUM

In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29747
5.9 MEDIUM

In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29745
5.5 MEDIUM KEV

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction …

Apr 5, 2024
CVE-2024-29744
5.5 MEDIUM

In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-29742
5.5 MEDIUM

In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29739
5.5 MEDIUM

In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-29738
5.5 MEDIUM

In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-27232
5.5 MEDIUM

In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no …

Apr 5, 2024
CVE-2024-27231
5.9 MEDIUM

In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Apr 5, 2024
CVE-2024-28065
5.9 MEDIUM

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

Apr 5, 2024
CVE-2024-3346
6.3 MEDIUM

A vulnerability was found in Byzoro Smart S80 up to 20240328. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 5, 2024
CVE-2024-31852
5.9 MEDIUM

LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes …

Apr 5, 2024
CVE-2023-49965
6.8 MEDIUM

SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

Apr 5, 2024
CVE-2024-2499
6.4 MEDIUM

The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordions' shortcode in all versions up to, …

Apr 5, 2024
CVE-2024-2380
4.6 MEDIUM

Stored XSS in graph rendering in Checkmk <2.3.0b4.

Apr 5, 2024
CVE-2023-5692
5.3 MEDIUM

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to …

Apr 5, 2024
CVE-2024-2447
6.5 MEDIUM

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post …

Apr 5, 2024
CVE-2024-29221
4.7 MEDIUM

Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the …

Apr 5, 2024
CVE-2024-28949
4.3 MEDIUM

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an …

Apr 5, 2024
CVE-2024-27437
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Disable auto-enable of exclusive INTx IRQ Currently for devices requiring masking at the irqchip …

Apr 5, 2024
CVE-2024-26814
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/fsl-mc: Block calling interrupt handler without trigger The eventfd_ctx trigger pointer of the vfio_fsl_mc_irq object …

Apr 5, 2024
CVE-2024-26813
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/platform: Create persistent IRQ handlers The vfio-platform SET_IRQS ioctl currently allows loopback triggering of an …

Apr 5, 2024
CVE-2024-26812
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnerability exists where the eventfd for INTx signaling can …

Apr 5, 2024
CVE-2024-26810
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask operations through config space changes to DisINTx may …

Apr 5, 2024
CVE-2024-26329
6.2 MEDIUM

Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.

Apr 5, 2024
CVE-2024-2509
6.5 MEDIUM

The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in …

Apr 5, 2024
CVE-2023-5973
4.3 MEDIUM

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved …

Apr 5, 2024
CVE-2024-31212
6.7 MEDIUM

InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can …

Apr 4, 2024
CVE-2024-31211
5.5 MEDIUM

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. …

Apr 4, 2024
CVE-2024-3316
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 4, 2024
CVE-2024-29981
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Apr 4, 2024
CVE-2024-29049
4.1 MEDIUM

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

Apr 4, 2024
CVE-2024-3315
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 4, 2024
CVE-2024-3314
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php. …

Apr 4, 2024
CVE-2024-3311
6.3 MEDIUM

A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability is the function ZipUtils.unZipFiles of …

Apr 4, 2024
CVE-2024-31204
6.1 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This …

Apr 4, 2024
CVE-2024-30270
6.2 MEDIUM

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This …

Apr 4, 2024
CVE-2024-30255
5.3 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are …

Apr 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.