Total
395554 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57492 | 1 Redox-os | 1 Redox | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton. | |||||
| CVE-2024-57491 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API without any token via the preHandle function. | |||||
| CVE-2024-57490 | 1 Ioffice | 1 Ioffice20 | 2026-06-17 | N/A | 7.7 HIGH |
| Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through a logical flaw. | |||||
| CVE-2024-57488 | 1 Code-projects | 1 Online Car Rental System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php. | |||||
| CVE-2024-57487 | 1 Code-projects | 1 Online Car Rental System | 2026-06-17 | N/A | 6.5 MEDIUM |
| In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server. | |||||
| CVE-2024-57459 | 1 Vishalmathur | 1 Cloudclassroom-php Project | 2026-06-17 | N/A | 7.3 HIGH |
| A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands. | |||||
| CVE-2024-57452 | 1 1000mz | 1 Chestnutcms | 2026-06-17 | N/A | 7.5 HIGH |
| ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder. | |||||
| CVE-2024-57451 | 1 1000mz | 1 Chestnutcms | 2026-06-17 | N/A | 7.5 HIGH |
| ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory. | |||||
| CVE-2024-57450 | 1 1000mz | 1 Chestnutcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function. | |||||
| CVE-2024-57440 | 1 Dlink | 2 Dsl-3788, Dsl-3788 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi | |||||
| CVE-2024-57439 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 4.9 MEDIUM |
| An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account. | |||||
| CVE-2024-57438 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 5.4 MEDIUM |
| Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles. | |||||
| CVE-2024-57437 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 6.5 MEDIUM |
| RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list. | |||||
| CVE-2024-57436 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 7.2 HIGH |
| RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie. | |||||
| CVE-2024-57435 | 1 Macrozheng | 1 Mall-tiny | 2026-06-17 | N/A | 6.5 MEDIUM |
| In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require authentication, which triggers a denial-of-service attack and service restart failure. | |||||
| CVE-2024-57434 | 1 Macrozheng | 1 Mall-tiny | 2026-06-17 | N/A | 8.8 HIGH |
| macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator. | |||||
| CVE-2024-57433 | 1 Macrozheng | 1 Mall-tiny | 2026-06-17 | N/A | 7.5 HIGH |
| macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state. | |||||
| CVE-2024-57432 | 1 Macrozheng | 1 Mall-tiny | 2026-06-17 | N/A | 7.5 HIGH |
| macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass. | |||||
| CVE-2024-57430 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 9.8 CRITICAL |
| An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation. | |||||
| CVE-2024-57429 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request. | |||||
