CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26193
6.4 MEDIUM

Azure Migrate Remote Code Execution Vulnerability

Apr 9, 2024
CVE-2024-26183
6.5 MEDIUM

Windows Kerberos Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-26172
5.5 MEDIUM

Windows DWM Core Library Information Disclosure Vulnerability

Apr 9, 2024
CVE-2024-26171
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-26168
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-21424
6.5 MEDIUM

Azure Compute Gallery Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-20685
5.9 MEDIUM

Azure Private 5G Core Denial of Service Vulnerability

Apr 9, 2024
CVE-2024-20669
6.7 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-20665
6.1 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Apr 9, 2024
CVE-2024-31868
6.1 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and exposure XSS attacks to normal users. This issue affects …

Apr 9, 2024
CVE-2024-31865
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run …

Apr 9, 2024
CVE-2024-31487
5.9 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2024-23662
5.3 MEDIUM

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and …

Apr 9, 2024
CVE-2023-48784
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command …

Apr 9, 2024
CVE-2023-47542
6.7 MEDIUM

A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and …

Apr 9, 2024
CVE-2023-47541
6.7 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 …

Apr 9, 2024
CVE-2023-47540
6.7 MEDIUM

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2.1 through 4.2.6, …

Apr 9, 2024
CVE-2024-28234
4.3 MEDIUM

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS …

Apr 9, 2024
CVE-2024-28190
5.4 MEDIUM

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in …

Apr 9, 2024
CVE-2024-31544
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, …

Apr 9, 2024
CVE-2024-31863
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to …

Apr 9, 2024
CVE-2024-31862
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are …

Apr 9, 2024
CVE-2022-47894
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin SAP.This issue affects Apache Zeppelin SAP: from 0.8.0 before 0.11.0. As this project is retired, we do not …

Apr 9, 2024
CVE-2021-28656
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue affects Apache Zeppelin Apache Zeppelin …

Apr 9, 2024
CVE-2024-31860
6.5 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that …

Apr 9, 2024
CVE-2024-31369
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-31368
6.5 MEDIUM

Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Apr 9, 2024
CVE-2024-30190
6.1 MEDIUM

A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0TA0), SCALANCE W1788-1 M12 (6GK5788-1GY01-0AA0), SCALANCE W1788-2 EEC M12 (6GK5788-2GY01-0TA0), SCALANCE W1788-2 …

Apr 9, 2024
CVE-2024-30189
6.1 MEDIUM

A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6GK5722-1FC00-0AA0) (All versions), SCALANCE …

Apr 9, 2024
CVE-2023-50821
6.2 MEDIUM

A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versions < V17 …

Apr 9, 2024
CVE-2024-1664
6.1 MEDIUM

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 9, 2024
CVE-2024-30218
6.5 MEDIUM

The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by …

Apr 9, 2024
CVE-2024-30217
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024
CVE-2024-30216
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024
CVE-2024-30215
4.8 MEDIUM

The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whenever a User visits the page. In …

Apr 9, 2024
CVE-2024-30214
4.8 MEDIUM

The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which are reflected in the server response. Under …

Apr 9, 2024
CVE-2024-28167
6.5 MEDIUM

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data …

Apr 9, 2024
CVE-2024-27898
5.3 MEDIUM

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind …

Apr 9, 2024
CVE-2024-23584
6.6 MEDIUM

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

Apr 8, 2024
CVE-2024-23079
6.2 MEDIUM

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-0083
6.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts …

Apr 8, 2024
CVE-2024-3466
5.5 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of …

Apr 8, 2024
CVE-2024-3465
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. …

Apr 8, 2024
CVE-2024-27631
6.0 MEDIUM

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

Apr 8, 2024
CVE-2024-3464
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The …

Apr 8, 2024
CVE-2024-28224
6.6 MEDIUM

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with …

Apr 8, 2024
CVE-2024-3458
6.3 MEDIUM

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation …

Apr 8, 2024
CVE-2024-3457
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The …

Apr 8, 2024
CVE-2024-3456
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 8, 2024
CVE-2024-3455
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.