CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31399
6.5 MEDIUM

Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may …

Jun 11, 2024
CVE-2024-31398
4.3 MEDIUM

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log …

Jun 11, 2024
CVE-2024-31397
4.9 MEDIUM

Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to …

Jun 11, 2024
CVE-2024-5530
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored …

Jun 11, 2024
CVE-2024-36360
9.8 CRITICAL

OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary …

Jun 11, 2024
CVE-2024-35329

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jun 11, 2024
CVE-2024-31404
4.3 MEDIUM

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to …

Jun 11, 2024
CVE-2024-31403
5.4 MEDIUM

Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.

Jun 11, 2024
CVE-2024-31401
9.0 CRITICAL

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the …

Jun 11, 2024
CVE-2024-31400
6.5 MEDIUM

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left …

Jun 11, 2024
CVE-2024-29855
9.0 CRITICAL

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

Jun 11, 2024
CVE-2023-7264
8.1 HIGH

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and …

Jun 11, 2024
CVE-2024-5090
6.4 MEDIUM

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOrigin Blog Widget in all versions up to, and …

Jun 11, 2024
CVE-2024-37176
5.5 MEDIUM

SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization …

Jun 11, 2024
CVE-2024-34691
6.5 MEDIUM

Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a …

Jun 11, 2024
CVE-2024-34690
5.4 MEDIUM

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation …

Jun 11, 2024
CVE-2024-34688
7.5 HIGH

Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may …

Jun 11, 2024
CVE-2024-34686
6.1 MEDIUM

Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a …

Jun 11, 2024
CVE-2024-34684
3.7 LOW

On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a …

Jun 11, 2024
CVE-2024-34683
6.5 MEDIUM

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, …

Jun 11, 2024
CVE-2024-33001
6.5 MEDIUM

SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding the service. An impact of this Denial …

Jun 11, 2024
CVE-2024-2473
5.3 MEDIUM

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to …

Jun 11, 2024
CVE-2024-28164
5.3 MEDIUM

SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing …

Jun 11, 2024
CVE-2024-0653
4.4 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.1 due …

Jun 11, 2024
CVE-2024-0627
6.4 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom field name column in all versions up to, …

Jun 11, 2024
CVE-2023-6748
4.3 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. …

Jun 11, 2024
CVE-2023-6745
6.4 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cpt' shortcode in all versions up to, and including, …

Jun 11, 2024
CVE-2024-37178
5.0 MEDIUM

SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can …

Jun 11, 2024
CVE-2024-37177
8.1 HIGH

SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are exposed over the network and it allows the …

Jun 11, 2024
CVE-2024-37130
7.3 HIGH

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit …

Jun 11, 2024
CVE-2024-22261
2.7 LOW

SQL-Injection in Harbor allows priviledge users to leak the task IDs

Jun 11, 2024
CVE-2024-22244
4.3 MEDIUM

Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

Jun 10, 2024
CVE-2022-37020
6.8 MEDIUM

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is …

Jun 10, 2024
CVE-2022-37019
6.8 MEDIUM

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is …

Jun 10, 2024
CVE-2024-37289
7.8 HIGH

An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker …

Jun 10, 2024
CVE-2024-37169
5.3 MEDIUM

@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Playright's …

Jun 10, 2024
CVE-2024-37168
5.3 MEDIUM

@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.10.9, 1.9.15, and 1.8.22, there are two separate …

Jun 10, 2024
CVE-2024-37166
8.9 HIGH

ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-controlled JavaScript code and trigger a Cross-Site Scripting (XSS) …

Jun 10, 2024
CVE-2024-36473
5.3 MEDIUM

Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local …

Jun 10, 2024
CVE-2024-36471
7.5 HIGH

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imports, which could cause Allura …

Jun 10, 2024
CVE-2024-36419
4.3 MEDIUM

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing …

Jun 10, 2024
CVE-2024-36359
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations. …

Jun 10, 2024
CVE-2024-36358
7.8 HIGH

A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local attacker to escalate privileges on affected installations. …

Jun 10, 2024
CVE-2024-36307
4.7 MEDIUM

A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive …

Jun 10, 2024
CVE-2024-36306
6.1 MEDIUM

A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine could allow a local attacker to …

Jun 10, 2024
CVE-2024-36305
7.8 HIGH

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jun 10, 2024
CVE-2024-36304
7.8 HIGH

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges …

Jun 10, 2024
CVE-2024-36303
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jun 10, 2024
CVE-2024-36302
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jun 10, 2024
CVE-2024-35242
8.8 HIGH

Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg …

Jun 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.