CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34717
5.3 MEDIUM

PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random …

May 14, 2024
CVE-2024-34712
6.5 MEDIUM

Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially …

May 14, 2024
CVE-2024-34687
6.5 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can …

May 14, 2024
CVE-2024-34358
5.3 MEDIUM

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, …

May 14, 2024
CVE-2024-34357
5.4 MEDIUM

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, …

May 14, 2024
CVE-2024-34356
5.4 MEDIUM

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, …

May 14, 2024
CVE-2024-34243
5.4 MEDIUM

Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

May 14, 2024
CVE-2024-34191
6.5 MEDIUM

htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files …

May 14, 2024
CVE-2024-33867
4.8 MEDIUM

An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.

May 14, 2024
CVE-2024-33866
5.5 MEDIUM

An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.

May 14, 2024
CVE-2024-33864
5.9 MEDIUM

An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file …

May 14, 2024
CVE-2024-33647
6.5 MEDIUM

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access …

May 14, 2024
CVE-2024-33498
5.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33497
6.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33496
6.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33495
6.5 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33494
6.5 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33009
4.2 MEDIUM

SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the …

May 14, 2024
CVE-2024-33008
4.9 MEDIUM

SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to …

May 14, 2024
CVE-2024-33004
4.3 MEDIUM

SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, …

May 14, 2024
CVE-2024-33002
6.1 MEDIUM

Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality …

May 14, 2024
CVE-2024-32733
6.1 MEDIUM

Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject …

May 14, 2024
CVE-2024-32731
5.5 MEDIUM

SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can …

May 14, 2024
CVE-2024-32354
6.0 MEDIUM

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

May 14, 2024
CVE-2024-32349
6.0 MEDIUM

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

May 14, 2024
CVE-2024-32077
5.4 MEDIUM

Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. Users are recommended to …

May 14, 2024
CVE-2024-31486
5.3 MEDIUM

A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. …

May 14, 2024
CVE-2024-30208
6.3 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-28135
5.0 MEDIUM

A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to …

May 14, 2024
CVE-2024-27947
5.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwarded to a specific …

May 14, 2024
CVE-2024-27946
6.5 MEDIUM

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in the installation directory of …

May 14, 2024
CVE-2024-26367
6.1 MEDIUM

Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote …

May 14, 2024
CVE-2024-25970
6.5 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to …

May 14, 2024
CVE-2024-25969
6.2 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this …

May 14, 2024
CVE-2024-25968
5.9 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit …

May 14, 2024
CVE-2024-25967
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading …

May 14, 2024
CVE-2024-25966
5.3 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, …

May 14, 2024
CVE-2024-25965
6.1 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit …

May 14, 2024
CVE-2024-1914
6.5 MEDIUM

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to …

May 14, 2024
CVE-2024-0870
5.3 MEDIUM

The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and …

May 14, 2024
CVE-2023-6812
4.3 MEDIUM

The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is …

May 14, 2024
CVE-2023-46280
6.5 MEDIUM

A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions …

May 14, 2024
CVE-2024-4854
6.4 MEDIUM

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet …

May 14, 2024
CVE-2024-4840
5.5 MEDIUM

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored …

May 14, 2024
CVE-2024-4823
6.5 MEDIUM

Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An …

May 14, 2024
CVE-2024-4822
6.5 MEDIUM

Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an attacker to partially take …

May 14, 2024
CVE-2024-4820
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

May 14, 2024
CVE-2024-4819
4.3 MEDIUM

A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

May 14, 2024
CVE-2024-4818
5.3 MEDIUM

A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. …

May 14, 2024
CVE-2024-4817
6.3 MEDIUM

A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.