Total
7908 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-42480 | 1 Clastix | 1 Kamaji | 2026-06-17 | N/A | 8.1 HIGH |
| Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2. | |||||
| CVE-2024-42406 | 1 Mattermost | 1 Mattermost Server | 2026-06-17 | N/A | 5.4 MEDIUM |
| Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files. | |||||
| CVE-2024-42354 | 1 Shopware | 1 Shopware | 2026-06-17 | N/A | 5.3 MEDIUM |
| Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to the final JSON. Prior to versions 6.6.5.1 and 6.5.8.13, the processing of the Criteria did not considered ManyToMany associations and so they were not considered properly and the protections didn't get used. This issue cannot be reproduced with the default entities by Shopware, but can be triggered with extensions. Update to Shopware 6.6.5.1 or 6.5.8.13 to receive a patch. For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin. | |||||
| CVE-2024-42048 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary code execution and privilege escalation. | |||||
| CVE-2024-42033 | 1 Huawei | 2 Emui, Harmonyos | 2026-06-17 | N/A | 6.9 MEDIUM |
| Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality. | |||||
| CVE-2024-42023 | 1 Veeam | 1 One | 2026-06-17 | N/A | 8.8 HIGH |
| An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely. | |||||
| CVE-2024-42022 | 1 Veeam | 1 One | 2026-06-17 | N/A | 5.3 MEDIUM |
| An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. | |||||
| CVE-2024-42021 | 1 Veeam | 1 One | 2026-06-17 | N/A | 6.5 MEDIUM |
| An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. | |||||
| CVE-2024-41934 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service via local access. | |||||
| CVE-2024-41926 | 1 Mattermost | 1 Mattermost Server | 2026-06-17 | N/A | 2.7 LOW |
| Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote. | |||||
| CVE-2024-41912 | 1 Hp | 1 Poly Clariti Manager | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls. | |||||
| CVE-2024-41905 | 1 Siemens | 1 Sinec Traffic Analyzer | 2026-06-17 | N/A | 6.8 MEDIUM |
| A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information. | |||||
| CVE-2024-41806 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain storage backends, uploads may become publicly available when the uploader uses versions master, palm, olive, nutmeg, maple, lilac, koa, or juniper. The patch in commit cb729a3ced0404736dfa0ae768526c82b608657b ensures that cohorts data uploaded to AWS S3 buckets is written with a private ACL. Beyond patching, deployers should also ensure that existing cohorts uploads have a private ACL, or that other precautions are taken to avoid public access. | |||||
| CVE-2024-41732 | 1 Sap | 1 Netweaver Application Server Abap | 2026-06-17 | N/A | 4.7 MEDIUM |
| SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application. | |||||
| CVE-2024-41703 | 1 Librechat | 1 Librechat | 2026-06-17 | N/A | 9.8 CRITICAL |
| LibreChat through 0.7.4-rc1 has incorrect access control for message updates. | |||||
| CVE-2024-41605 | 2026-06-17 | N/A | 8.4 HIGH | ||
| In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed. | |||||
| CVE-2024-41600 | 1 Talelin | 1 Lin-cms-spring-boot | 2026-06-17 | N/A | 7.5 HIGH |
| Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component. | |||||
| CVE-2024-41518 | 1 Mecodia | 1 Feripro | 2026-06-17 | N/A | 7.5 HIGH |
| An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants. | |||||
| CVE-2024-41332 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories. | |||||
| CVE-2024-41309 | 1 Enjayworld | 1 Enjay Crm | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system. | |||||
