Vulnerabilities (CVE)

Total 395684 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45283 2026-06-17 N/A 6.0 MEDIUM
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.
CVE-2024-45282 1 Sap 1 S\/4 Hana 2026-06-17 N/A 4.3 MEDIUM
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.
CVE-2024-45281 1 Sap 1 Businessobjects Business Intelligence Platform 2026-06-17 N/A 5.8 MEDIUM
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.
CVE-2024-45280 2026-06-17 N/A 4.8 MEDIUM
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
CVE-2024-45279 2026-06-17 N/A 6.1 MEDIUM
Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
CVE-2024-45278 1 Sap 1 Commerce Backoffice 2026-06-17 N/A 5.4 MEDIUM
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
CVE-2024-45277 1 Sap 1 Hana-client 2026-06-17 N/A 4.3 MEDIUM
The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.
CVE-2024-45276 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2026-06-17 N/A 7.5 HIGH
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
CVE-2024-45275 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2026-06-17 N/A 9.8 CRITICAL
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
CVE-2024-45274 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2026-06-17 N/A 9.8 CRITICAL
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
CVE-2024-45273 2 Helmholz, Mbconnectline 27 Myrex24 V2 Virtual Server, Rex 100, Rex 100 Firmware and 24 more 2026-06-17 N/A 8.4 HIGH
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
CVE-2024-45272 2 Helmholz, Mbconnectline 23 Myrex24 V2 Virtual Server, Rex 200, Rex 200 Firmware and 20 more 2026-06-17 N/A 7.5 HIGH
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
CVE-2024-45271 2 Helmholz, Mbconnectline 4 Rex 100, Rex 100 Firmware, Mbnet.mini and 1 more 2026-06-17 N/A 8.4 HIGH
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
CVE-2024-45270 1 Majeedraza 1 Carousel Slider 2026-06-17 N/A 4.3 MEDIUM
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.
CVE-2024-45269 1 Majeedraza 1 Carousel Slider 2026-06-17 N/A 4.3 MEDIUM
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site.
CVE-2024-45265 1 Skyss 1 Arfa-cms 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
CVE-2024-45264 1 Skyss 1 Arfa-cms 2026-06-17 N/A 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.
CVE-2024-45263 1 Gl-inet 42 A1300, A1300 Firmware, Ar300m and 39 more 2026-06-17 N/A 8.8 HIGH
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.
CVE-2024-45262 1 Gl-inet 42 A1300, A1300 Firmware, Ar300m and 39 more 2026-06-17 N/A 8.8 HIGH
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.
CVE-2024-45261 1 Gl-inet 42 A1300, A1300 Firmware, Ar300m and 39 more 2026-06-17 N/A 8.0 HIGH
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.