Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per…
Moodle
Mitigation only
HIGH 8.8
CVE-2024-28118
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra…
Grav
1.7.45+
HIGH 8.8
CVE-2024-28119
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra…
Grav
1.7.45+
HIGH 8.8
CVE-2024-28116EPSS 6%
Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI…
Grav
1.7.45+
HIGH 8.8
CVE-2024-28117
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger…
Grav
1.7.45+
MEDIUM 6.6
CVE-2024-22724
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator prof…
Oscommerce
No fix yet
HIGH 8.8
CVE-2024-2016
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontr…
Zhicms
No fix yet
MEDIUM 6.6
CVE-2024-25359
An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.
Lagom
Mitigation only
HIGH 7.8
CVE-2024-24520
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
Leptoncms
No fix yet
HIGH 7.5
CVE-2024-28396
An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.
Orders \(csv\, Excel\) Export Pro
after 6.0.2
MEDIUM 6.1
CVE-2024-2610
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulne…
Firefox
115.9.0 / 124.0+
HIGH 7.5
CVE-2024-24230
Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to exec…
Mitigation only
HIGH 8.8
CVE-2024-28847
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…
Openmetadata
1.2.4+
HIGH 8.8
CVE-2024-28848EPSS 8%
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…
Openmetadata
1.2.4+
HIGH 8.8
CVE-2024-28253EPSS 13%
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…
Openmetadata
1.3.1+
HIGH 7.2
CVE-2024-2497
A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/p…
Raspap
No fix yet
HIGH 8.8
CVE-2024-27756
GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
Glpi
after 10.0.12
HIGH 8.8
CVE-2024-28424
zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. Th…
Zenml
No fix yet
HIGH 7.5
CVE-2022-46070
GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.
Gv Asmanager
Mitigation only
HIGH 8.6
CVE-2024-23278
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS…
Ipados
10.4 / 13.6.5+
CRITICAL 9.8
CVE-2023-41503
Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
Student Enrollment
Mitigation only
CRITICAL 9.8
CVE-2024-0917
remote code execution in paddlepaddle/paddle 2.6.0
Paddlepaddle
No fix yet
HIGH 7.5
CVE-2024-24278
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to…
Teamwire
after 2.4.0
HIGH 7.2
CVE-2024-27622
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerabil…
Cms Made Simple
No fix yet
MEDIUM 6.1
CVE-2024-27627
A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript cod…
No fix yet
HIGH 7.2
CVE-2024-22188
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges o…
TYPO3
8.7.57 / 9.5.46+
CRITICAL 9.3
CVE-2024-25293
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
Mjml App
No fix yet
CRITICAL 9.8
CVE-2024-25180
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is dispu…
Pdfmake
No fix yet
CRITICAL 9.8
CVE-2024-25291
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
Deskfiler
No fix yet
CRITICAL 9.8
CVE-2024-24525
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the…
Epointwebbuilder
Mitigation only