Vulnerabilities (CVE)

Total 398493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-21740 2026-06-17 N/A 7.4 HIGH
Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.
CVE-2024-21739 2026-06-17 N/A 5.3 MEDIUM
Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control.
CVE-2024-21738 1 Sap 1 Netweaver Application Server Abap 2026-06-17 N/A 4.1 MEDIUM
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.
CVE-2024-21737 1 Sap 1 Application Interface Framework 2026-06-17 N/A 8.4 HIGH
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and availability.
CVE-2024-21736 1 Sap 1 S\/4hana Finance 2026-06-17 N/A 6.4 MEDIUM
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of the application.
CVE-2024-21735 1 Sap 1 Lt Replication Server 2026-06-17 N/A 7.3 HIGH
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This could allow an attacker with high privileges to perform unintended actions, resulting in escalation of privileges, which has High impact on confidentiality, integrity and availability of the system.
CVE-2024-21734 1 Sap 1 Marketing 2026-06-17 N/A 3.7 LOW
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the application.
CVE-2024-21733 1 Apache 1 Tomcat 2026-06-17 N/A 5.3 MEDIUM
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
CVE-2024-21732 1 Flycms Project 1 Flycms 2026-06-17 N/A 6.1 MEDIUM
FlyCms through abbaa5a allows XSS via the permission management feature.
CVE-2024-21731 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
CVE-2024-21730 1 Joomla 1 Joomla\! 2026-06-17 N/A 5.4 MEDIUM
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
CVE-2024-21729 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
CVE-2024-21728 1 Smartcalc 1 Osticky 2026-06-17 N/A 6.1 MEDIUM
An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a base64 malicious URL.
CVE-2024-21727 1 Digital-peak 1 Dpcalendar 2026-06-17 N/A 6.1 MEDIUM
XSS vulnerability in DP Calendar component for Joomla.
CVE-2024-21726 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.5 MEDIUM
Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2024-21725 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
CVE-2024-21724 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.1 MEDIUM
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
CVE-2024-21723 1 Joomla 1 Joomla\! 2026-06-17 N/A 4.3 MEDIUM
Inadequate parsing of URLs could result into an open redirect.
CVE-2024-21722 1 Joomla 1 Joomla\! 2026-06-17 N/A 6.3 MEDIUM
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
CVE-2024-21703 2 Atlassian, Microsoft 3 Confluence Data Center, Confluence Server, Windows 2026-06-17 N/A 6.4 MEDIUM
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 * Confluence Data Center and Server 8.5: Upgrade to a release greater than or equal to 8.5.5 * Confluence Data Center and Server 8.7: Upgrade to a release greater than or equal to 8.7.2 * Confluence Data Center and Server 8.8: Upgrade to a release greater than or equal to 8.8.0 See the release notes (https://confluence.atlassian.com/conf88/confluence-release-notes-1354501008.html ). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives ). This vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot.