CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29386
5.4 MEDIUM

projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.

Apr 4, 2024
CVE-2024-24795
6.3 MEDIUM

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an …

Apr 4, 2024
CVE-2024-22023
5.3 MEDIUM

An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to …

Apr 4, 2024
CVE-2024-30254
5.8 MEDIUM

MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1.4 allows overwriting arbitrary files if the …

Apr 4, 2024
CVE-2024-29193
6.1 MEDIUM

gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The index page (`index.html`) shows the available streams by …

Apr 4, 2024
CVE-2024-2660
6.4 MEDIUM

Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, …

Apr 4, 2024
CVE-2024-27268
5.9 MEDIUM

IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker …

Apr 4, 2024
CVE-2024-25709
6.1 MEDIUM

There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may allow a remote, authenticated attacker to …

Apr 4, 2024
CVE-2024-25708
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.1 and below that may allow a remote, …

Apr 4, 2024
CVE-2024-25706
6.1 MEDIUM

There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL …

Apr 4, 2024
CVE-2024-25705
5.4 MEDIUM

There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below on Windows and Linux that allows a …

Apr 4, 2024
CVE-2024-25700
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 and below that may allow a remote, …

Apr 4, 2024
CVE-2024-25698
6.1 MEDIUM

There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that …

Apr 4, 2024
CVE-2024-25697
5.4 MEDIUM

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.1 and below that may allow a remote, authenticated attacker to create a …

Apr 4, 2024
CVE-2024-25696
4.8 MEDIUM

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.0 and below that may allow a remote, authenticated attacker to create a …

Apr 4, 2024
CVE-2024-25692
5.4 MEDIUM

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.1 and below that may in some cases allow a remote, unauthenticated attacker …

Apr 4, 2024
CVE-2024-25690
4.7 MEDIUM

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.1 and below that may allow a remote, unauthenticated attacker to create a …

Apr 4, 2024
CVE-2024-31215
6.3 MEDIUM

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check …

Apr 4, 2024
CVE-2024-31209
5.3 MEDIUM

oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuration_worker:get_provider_configuration/1` or `oidcc_provider_configuration_worker:get_jwks/1`. This issue …

Apr 4, 2024
CVE-2024-31207
5.9 MEDIUM

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for …

Apr 4, 2024
CVE-2024-2103
6.5 MEDIUM

Inclusion of undocumented features vulnerability accessible when logged on with a privileged access level on the following Schweitzer Engineering Laboratories relays could allow the relay …

Apr 4, 2024
CVE-2024-3250
6.5 MEDIUM

It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files …

Apr 4, 2024
CVE-2024-29191
6.1 MEDIUM

gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. The links page (`links.html`) appends the `src` GET parameter …

Apr 4, 2024
CVE-2024-29182
6.1 MEDIUM

Collabora Online is a collaborative online office suite based on LibreOffice. A stored cross-site scripting vulnerability was found in Collabora Online. An attacker could create …

Apr 4, 2024
CVE-2024-28182
5.3 MEDIUM

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number …

Apr 4, 2024
CVE-2024-3296
5.9 MEDIUM

A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To …

Apr 4, 2024
CVE-2024-3262
5.5 MEDIUM

Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about …

Apr 4, 2024
CVE-2024-26809
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: release elements in clone only from destroy path Clone already always provides a …

Apr 4, 2024
CVE-2024-26808
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain Remove netdevice from inet/ingress basechain in case NETDEV_UNREGISTER …

Apr 4, 2024
CVE-2024-26807
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Both cadence-quadspi ->runtime_suspend() and ->runtime_resume() implementations start with: struct cqspi_st *cqspi = dev_get_drvdata(dev); struct spi_controller …

Apr 4, 2024
CVE-2024-26806
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks The ->runtime_suspend() and ->runtime_resume() …

Apr 4, 2024
CVE-2024-26805
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter syzbot reported the following uninit-value access issue [1]: netlink_to_full_skb() creates …

Apr 4, 2024
CVE-2024-26804
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth syzkaller triggered following kasan splat: BUG: KASAN: use-after-free in …

Apr 4, 2024
CVE-2024-26803
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: veth: clear GRO when clearing XDP even when down veth sets NETIF_F_GRO automatically when …

Apr 4, 2024
CVE-2024-26802
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: stmmac: Clear variable when destroying workqueue Currently when suspending driver and stopping workqueue it is …

Apr 4, 2024
CVE-2024-26801
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT …

Apr 4, 2024
CVE-2024-26799
6.2 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix uninitialized pointer dmactl In the case where __lpass_get_dmactl_handle is called and the …

Apr 4, 2024
CVE-2024-26798
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038d70 (fbdev: fbcon: Properly revert …

Apr 4, 2024
CVE-2024-26796
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drivers: perf: ctr_get_width function for legacy is not defined With parameters CONFIG_RISCV_PMU_LEGACY=y and CONFIG_RISCV_PMU_SBI=n linux …

Apr 4, 2024
CVE-2024-26795
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: Sparse-Memory/vmemmap out-of-bounds fix Offset vmemmap so that the first page of vmemmap will be …

Apr 4, 2024
CVE-2024-26790
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read There is chip (ls1028a) …

Apr 4, 2024
CVE-2024-26788
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: init irq after reg initialization Initialize the qDMA irqs after the registers are …

Apr 4, 2024
CVE-2024-26787
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: mmci: stm32: fix DMA API overlapping mappings warning Turning on CONFIG_DMA_API_DEBUG_SG results in the …

Apr 4, 2024
CVE-2024-26786
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix iopt_access_list_id overwrite bug Syzkaller reported the following WARN_ON: WARNING: CPU: 1 PID: 4738 …

Apr 4, 2024
CVE-2024-26785
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix protection fault in iommufd_test_syz_conv_iova Syzkaller reported the following bug: general protection fault, probably …

Apr 4, 2024
CVE-2024-26784
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: Fix NULL dereference on scmi_perf_domain removal On unloading of the scmi_perf_domain module got …

Apr 4, 2024
CVE-2024-26783
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index With numa balancing on, …

Apr 4, 2024
CVE-2024-26781
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible deadlock in subflow diag Syzbot and Eric reported a lockdep splat in …

Apr 4, 2024
CVE-2024-26780
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix task hung while purging oob_skb in GC. syzbot reported a task hung; at …

Apr 4, 2024
CVE-2024-26750
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop oob_skb ref before purging queue in GC. syzbot reported another task hung in …

Apr 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.