CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51440
7.5 HIGH

A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (All versions), SIPLUS NET CP 343-1 (6AG1343-1EX30-7XE0) (All …

Feb 13, 2024
CVE-2023-50236
7.8 HIGH

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissions in …

Feb 13, 2024
CVE-2023-49125
7.8 HIGH

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions < V36.0.198), Solid …

Feb 13, 2024
CVE-2023-48364
6.5 MEDIUM

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC …

Feb 13, 2024
CVE-2023-48363
6.5 MEDIUM

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC …

Feb 13, 2024
CVE-2024-22454
8.8 HIGH

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit …

Feb 13, 2024
CVE-2024-22445
7.2 HIGH

Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, …

Feb 13, 2024
CVE-2023-6815
6.5 MEDIUM

Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/120SFCPU all versions and MELSEC iQ-R Series SIL2 Process CPU R08/16/32/120PSFCPU all …

Feb 13, 2024
CVE-2024-25914
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Photoboxone SMTP Mail.This issue affects SMTP Mail: from n/a through 1.3.20.

Feb 13, 2024
CVE-2024-21491
5.9 MEDIUM

Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths …

Feb 13, 2024
CVE-2023-52431
8.8 HIGH

The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if …

Feb 13, 2024
CVE-2022-48623
9.1 CRITICAL

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of …

Feb 13, 2024
CVE-2024-25643
4.3 MEDIUM

The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in …

Feb 13, 2024
CVE-2024-24741
4.3 MEDIUM

SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check …

Feb 13, 2024
CVE-2024-22129
5.4 MEDIUM

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to …

Feb 13, 2024
CVE-2024-22024
8.3 HIGH

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways …

Feb 13, 2024
CVE-2024-25642
7.4 HIGH

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the …

Feb 13, 2024
CVE-2024-24743
8.6 HIGH

SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file …

Feb 13, 2024
CVE-2024-24742
4.1 MEDIUM

SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF …

Feb 13, 2024
CVE-2024-24740
5.3 MEDIUM

SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain …

Feb 13, 2024
CVE-2024-24739
6.3 MEDIUM

SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact …

Feb 13, 2024
CVE-2024-22132
7.4 HIGH

SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behaviour of the system …

Feb 13, 2024
CVE-2024-22131
9.1 CRITICAL

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a …

Feb 13, 2024
CVE-2024-22130
7.6 HIGH

Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF …

Feb 13, 2024
CVE-2023-50358
5.8 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 13, 2024
CVE-2023-47218
5.8 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 13, 2024
CVE-2024-22128
4.7 MEDIUM

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently …

Feb 13, 2024
CVE-2024-22126
6.1 MEDIUM

The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them …

Feb 13, 2024
CVE-2024-25407
7.5 HIGH

SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service …

Feb 13, 2024
CVE-2023-52060
4.3 MEDIUM

A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.

Feb 13, 2024
CVE-2023-52059
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description …

Feb 13, 2024
CVE-2023-49339
6.5 MEDIUM

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Feb 13, 2024
CVE-2023-42374
9.8 CRITICAL

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted …

Feb 13, 2024
CVE-2024-25112
5.5 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 …

Feb 12, 2024
CVE-2024-24826
5.5 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in …

Feb 12, 2024
CVE-2024-1454
3.4 LOW

The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator …

Feb 12, 2024
CVE-2023-52430
6.1 MEDIUM

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either …

Feb 12, 2024
CVE-2023-28018
5.5 MEDIUM

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this …

Feb 12, 2024
CVE-2024-24337
8.0 HIGH

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into …

Feb 12, 2024
CVE-2024-23763
9.8 CRITICAL

SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.

Feb 12, 2024
CVE-2024-23762
7.8 HIGH

Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

Feb 12, 2024
CVE-2024-23761
9.8 CRITICAL

Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

Feb 12, 2024
CVE-2024-23760
2.7 LOW

Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

Feb 12, 2024
CVE-2024-23759
9.8 CRITICAL

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

Feb 12, 2024
CVE-2024-23833
7.5 HIGH

OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an …

Feb 12, 2024
CVE-2024-1459
5.3 MEDIUM

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for …

Feb 12, 2024
CVE-2024-1250
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with …

Feb 12, 2024
CVE-2024-25110
9.8 CRITICAL

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue …

Feb 12, 2024
CVE-2024-25108
9.9 CRITICAL

Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than …

Feb 12, 2024
CVE-2022-22506
4.6 MEDIUM

IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293.

Feb 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.