Total
11058 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-42493 | 1 Dorsettcontrols | 1 Infoscan | 2026-06-17 | N/A | 5.3 MEDIUM |
| Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login. | |||||
| CVE-2024-42486 | 1 Cilium | 1 Cilium | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster. | |||||
| CVE-2024-42435 | 1 Zoom | 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more | 2026-06-17 | N/A | 4.9 MEDIUM |
| Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access. | |||||
| CVE-2024-42394 | 2 Arubanetworks, Hp | 2 Arubaos, Instantos | 2026-06-17 | N/A | 9.8 CRITICAL |
| There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. | |||||
| CVE-2024-42351 | 1 Galaxyproject | 1 Galaxy | 2026-06-17 | N/A | 6.5 MEDIUM |
| Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to release_21.05) were amended with the below patch. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
| CVE-2024-42339 | 1 Cyberark | 1 Identity | 2026-06-17 | N/A | 4.3 MEDIUM |
| CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-42338 | 1 Cyberark | 1 Identity | 2026-06-17 | N/A | 4.3 MEDIUM |
| CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-42337 | 1 Cyberark | 1 Identity | 2026-06-17 | N/A | 4.3 MEDIUM |
| CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-42222 | 1 Apache | 1 Cloudstack | 2026-06-17 | N/A | 4.3 MEDIUM |
| In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. This vulnerability compromises tenant isolation, potentially leading to unauthorised access to network details, configurations and data. Affected users are advised to upgrade to version 4.19.1.1 to address this issue. Users on older versions of CloudStack considering to upgrade, can skip 4.19.1.0 and upgrade directly to 4.19.1.1. | |||||
| CVE-2024-42209 | 1 Hcltech | 1 Connections | 2026-06-17 | N/A | 3.5 LOW |
| HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data. | |||||
| CVE-2024-42208 | 1 Hcltech | 1 Connections | 2026-06-17 | N/A | 3.5 LOW |
| HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data. | |||||
| CVE-2024-42179 | 1 Hcltech | 1 Dryice Myxalytics | 2026-06-17 | N/A | 2.0 LOW |
| HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version. | |||||
| CVE-2024-42049 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection. | |||||
| CVE-2024-42019 | 1 Veeam | 1 One | 2026-06-17 | N/A | 8.0 HIGH |
| A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication. | |||||
| CVE-2024-42010 | 2026-06-17 | N/A | 7.5 HIGH | ||
| mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information. | |||||
| CVE-2024-42006 | 1 Keyfactor | 1 Aws Orchestrator | 2026-06-17 | N/A | 7.5 HIGH |
| Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure. | |||||
| CVE-2024-41736 | 1 Sap | 1 Permit To Work | 2026-06-17 | N/A | 4.3 MEDIUM |
| Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise be restricted causing low impact on the confidentiality of the application. | |||||
| CVE-2024-41733 | 1 Sap | 1 Commerce | 2026-06-17 | N/A | 5.3 MEDIUM |
| In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability | |||||
| CVE-2024-41723 | 1 F5 | 21 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 18 more | 2026-06-17 | N/A | 4.3 MEDIUM |
| Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |||||
| CVE-2024-41701 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
