Total
395565 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57777 | 1 Lanproxy Project | 1 Lanproxy | 2026-06-17 | N/A | 5.1 MEDIUM |
| Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information | |||||
| CVE-2024-57776 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.6 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57775 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 8.8 HIGH |
| JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid. | |||||
| CVE-2024-57774 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57773 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57772 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57771 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57770 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 8.8 HIGH |
| JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id. | |||||
| CVE-2024-57769 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 8.8 HIGH |
| JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser. | |||||
| CVE-2024-57768 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 9.8 CRITICAL |
| JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key. | |||||
| CVE-2024-57767 | 1 Wangl1989 | 1 Mysiteforme | 2026-06-17 | N/A | 8.6 HIGH |
| MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download. | |||||
| CVE-2024-57766 | 1 Wangl1989 | 1 Mysiteforme | 2026-06-17 | N/A | 9.1 CRITICAL |
| MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField. | |||||
| CVE-2024-57765 | 1 Wangl1989 | 1 Mysiteforme | 2026-06-17 | N/A | 7.5 HIGH |
| MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list. | |||||
| CVE-2024-57764 | 1 Wangl1989 | 1 Mysiteforme | 2026-06-17 | N/A | 9.1 CRITICAL |
| MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add. | |||||
| CVE-2024-57763 | 1 Wangl1989 | 1 Mysiteforme | 2026-06-17 | N/A | 9.1 CRITICAL |
| MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField. | |||||
| CVE-2024-57762 | 1 Wangl1989 | 1 Mysiteforme | 2026-06-17 | N/A | 7.5 HIGH |
| MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. | |||||
| CVE-2024-57761 | 1 Huayi-tec | 1 Jeewms | 2026-06-17 | N/A | 8.1 HIGH |
| An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-57760 | 1 Jeewms | 1 Jeewms | 2026-06-17 | N/A | 6.5 MEDIUM |
| JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java. | |||||
| CVE-2024-57757 | 1 Jeewms | 1 Jeewms | 2026-06-17 | N/A | 7.5 HIGH |
| JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava. | |||||
| CVE-2024-57728 | 1 Simple-help | 1 Simplehelp | 2026-06-17 | N/A | 7.2 HIGH |
| SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. | |||||
