Vulnerabilities (CVE)

Total 395565 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57777 1 Lanproxy Project 1 Lanproxy 2026-06-17 N/A 5.1 MEDIUM
Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information
CVE-2024-57776 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.6 MEDIUM
A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57775 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 8.8 HIGH
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
CVE-2024-57774 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57773 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57772 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57771 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57770 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 8.8 HIGH
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
CVE-2024-57769 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 8.8 HIGH
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
CVE-2024-57768 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 9.8 CRITICAL
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
CVE-2024-57767 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 8.6 HIGH
MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CVE-2024-57766 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 9.1 CRITICAL
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.
CVE-2024-57765 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 7.5 HIGH
MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CVE-2024-57764 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 9.1 CRITICAL
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.
CVE-2024-57763 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 9.1 CRITICAL
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.
CVE-2024-57762 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 7.5 HIGH
MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CVE-2024-57761 1 Huayi-tec 1 Jeewms 2026-06-17 N/A 8.1 HIGH
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-57760 1 Jeewms 1 Jeewms 2026-06-17 N/A 6.5 MEDIUM
JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.
CVE-2024-57757 1 Jeewms 1 Jeewms 2026-06-17 N/A 7.5 HIGH
JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.
CVE-2024-57728 1 Simple-help 1 Simplehelp 2026-06-17 N/A 7.2 HIGH
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.