CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31862
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are …

Apr 9, 2024
CVE-2022-47894
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not …

Apr 9, 2024
CVE-2021-28656
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin …

Apr 9, 2024
CVE-2024-31860
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that …

Apr 9, 2024
CVE-2024-31369
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-31368
6.5 MEDIUM

Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-30190
6.1 MEDIUM

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 …

Apr 9, 2024
CVE-2024-30189
6.1 MEDIUM

A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (All versions), SCALANCE …

Apr 9, 2024
CVE-2023-50821
6.2 MEDIUM

A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versions < V17 …

Apr 9, 2024
CVE-2024-1664
6.1 MEDIUM

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 9, 2024
CVE-2024-30218
6.5 MEDIUM

The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by …

Apr 9, 2024
CVE-2024-30217
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024
CVE-2024-30216
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024
CVE-2024-30215
4.8 MEDIUM

The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whenever a User visits the page. In …

Apr 9, 2024
CVE-2024-30214
4.8 MEDIUM

The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which are reflected in the server response. Under …

Apr 9, 2024
CVE-2024-28167
6.5 MEDIUM

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data …

Apr 9, 2024
CVE-2024-27898
5.3 MEDIUM

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind …

Apr 9, 2024
CVE-2024-23584
6.6 MEDIUM

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

Apr 8, 2024
CVE-2024-23079
6.2 MEDIUM

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-0083
6.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts …

Apr 8, 2024
CVE-2024-3466
5.5 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of …

Apr 8, 2024
CVE-2024-3465
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. …

Apr 8, 2024
CVE-2024-27631
6.0 MEDIUM

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

Apr 8, 2024
CVE-2024-3464
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The …

Apr 8, 2024
CVE-2024-28224
6.6 MEDIUM

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with …

Apr 8, 2024
CVE-2024-3458
6.3 MEDIUM

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation …

Apr 8, 2024
CVE-2024-3457
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The …

Apr 8, 2024
CVE-2024-3456
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 8, 2024
CVE-2024-3455
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 8, 2024
CVE-2024-3445
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /karyawan/laporan_filter. …

Apr 8, 2024
CVE-2024-31447
5.3 MEDIUM

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when …

Apr 8, 2024
CVE-2024-3444
4.7 MEDIUM

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file …

Apr 8, 2024
CVE-2024-3442
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. This affects an unknown part of the file /Employee/delete_leave.php. The manipulation …

Apr 8, 2024
CVE-2024-31221
5.9 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web …

Apr 8, 2024
CVE-2024-31205
4.2 MEDIUM

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set …

Apr 8, 2024
CVE-2024-30269
5.3 MEDIUM

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via …

Apr 8, 2024
CVE-2024-3441
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Apr 8, 2024
CVE-2024-3440
4.7 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Apr 8, 2024
CVE-2024-2511
5.9 MEDIUM

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations …

Apr 8, 2024
CVE-2024-31812
6.5 MEDIUM

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.

Apr 8, 2024
CVE-2024-31806
6.5 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.

Apr 8, 2024
CVE-2024-31805
6.5 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.

Apr 8, 2024
CVE-2024-26811
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid …

Apr 8, 2024
CVE-2023-52385
6.2 MEDIUM

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52364
6.3 MEDIUM

Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.

Apr 8, 2024
CVE-2024-31375
5.4 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.

Apr 8, 2024
CVE-2024-31357
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store …

Apr 8, 2024
CVE-2024-23192
6.1 MEDIUM

RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or …

Apr 8, 2024
CVE-2024-23191
5.4 MEDIUM

Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2024-23190
5.4 MEDIUM

Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.