Vulnerabilities (CVE)

Total 395554 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57428 1 Phpjabbers 1 Cinema Booking System 2026-06-17 N/A 9.3 CRITICAL
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.
CVE-2024-57427 1 Phpjabbers 1 Cinema Booking System 2026-06-17 N/A 6.1 MEDIUM
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.
CVE-2024-57426 2026-06-17 N/A 7.3 HIGH
NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.
CVE-2024-57423 1 Vishalmathur 1 Cloudclassroom-php Project 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.
CVE-2024-57412 2026-06-17 N/A 7.5 HIGH
An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.
CVE-2024-57409 1 Beian.miit 1 Cool-admin-java 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.
CVE-2024-57408 1 Beian.miit 1 Cool-admin-java 2026-06-17 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-57407 2026-06-17 N/A 7.3 HIGH
An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-57401 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function.
CVE-2024-57395 2026-06-17 N/A 9.8 CRITICAL
Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters.
CVE-2024-57394 1 Qianxin 1 Tianqing Endpoint Security Management System 2026-06-17 N/A 8.8 HIGH
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.
CVE-2024-57392 2026-06-17 N/A 7.5 HIGH
Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.
CVE-2024-57386 1 Wallosapp 1 Wallos 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.
CVE-2024-57378 2026-06-17 N/A 7.3 HIGH
Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.
CVE-2024-57376 1 Dlink 12 Dsr-1000n, Dsr-1000n Firmware, Dsr-150 and 9 more 2026-06-17 N/A 8.8 HIGH
Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.
CVE-2024-57375 2026-06-17 N/A 2.4 LOW
Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) via certain deselect actions.
CVE-2024-57373 2026-06-17 N/A 8.1 HIGH
Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise.
CVE-2024-57372 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters
CVE-2024-57369 1 Typecho 1 Typecho 2026-06-17 N/A 6.4 MEDIUM
Clickjacking vulnerability in typecho v1.2.1.
CVE-2024-57360 2026-06-17 N/A 5.5 MEDIUM
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.