CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30687

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30686

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30684

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-1664
6.1 MEDIUM

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Apr 9, 2024
CVE-2024-30683

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30681

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30680

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30679

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30678

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30676

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 9, 2024
CVE-2024-30218
6.5 MEDIUM

The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by …

Apr 9, 2024
CVE-2024-30217
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024
CVE-2024-30216
4.3 MEDIUM

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, …

Apr 9, 2024
CVE-2024-30215
4.8 MEDIUM

The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whenever a User visits the page. In …

Apr 9, 2024
CVE-2024-30214
4.8 MEDIUM

The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which are reflected in the server response. Under …

Apr 9, 2024
CVE-2024-2975
8.8 HIGH

A race condition was identified through which privilege escalation was possible in certain configurations.

Apr 9, 2024
CVE-2024-28167
6.5 MEDIUM

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data …

Apr 9, 2024
CVE-2024-27983
8.2 HIGH

An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. …

Apr 9, 2024
CVE-2024-27901
7.2 HIGH

SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to …

Apr 9, 2024
CVE-2024-27899
8.8 HIGH

Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the …

Apr 9, 2024
CVE-2024-27898
5.3 MEDIUM

SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind …

Apr 9, 2024
CVE-2024-25646
7.7 HIGH

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation …

Apr 9, 2024
CVE-2024-31047
3.3 LOW

An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function …

Apr 8, 2024
CVE-2024-23584
6.6 MEDIUM

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

Apr 8, 2024
CVE-2024-23084
7.5 HIGH

Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23081
3.3 LOW

ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23079
6.2 MEDIUM

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-22949
9.1 CRITICAL

JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not …

Apr 8, 2024
CVE-2024-27632
8.8 HIGH

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

Apr 8, 2024
CVE-2024-0083
6.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts …

Apr 8, 2024
CVE-2024-0082
8.2 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the …

Apr 8, 2024
CVE-2024-3466
5.5 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of …

Apr 8, 2024
CVE-2024-3465
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. …

Apr 8, 2024
CVE-2024-27631
6.0 MEDIUM

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

Apr 8, 2024
CVE-2024-27630
7.5 HIGH

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file …

Apr 8, 2024
CVE-2024-3464
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The …

Apr 8, 2024
CVE-2024-3463
3.5 LOW

A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The …

Apr 8, 2024
CVE-2024-24279
8.8 HIGH

An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower …

Apr 8, 2024
CVE-2024-23086
9.8 CRITICAL

Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23085
7.5 HIGH

Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-23078
9.1 CRITICAL

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-28270
8.1 HIGH

An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.

Apr 8, 2024
CVE-2024-28224
6.6 MEDIUM

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with …

Apr 8, 2024
CVE-2024-3458
6.3 MEDIUM

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation …

Apr 8, 2024
CVE-2024-3457
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The …

Apr 8, 2024
CVE-2024-23082

ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe …

Apr 8, 2024
CVE-2023-7164
7.5 HIGH

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's …

Apr 8, 2024
CVE-2024-3456
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 8, 2024
CVE-2024-3455
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 8, 2024
CVE-2024-3445
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /karyawan/laporan_filter. …

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.