Total
395554 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57428 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 9.3 CRITICAL |
| A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking. | |||||
| CVE-2024-57427 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 6.1 MEDIUM |
| PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks. | |||||
| CVE-2024-57426 | 2026-06-17 | N/A | 7.3 HIGH | ||
| NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries. | |||||
| CVE-2024-57423 | 1 Vishalmathur | 1 Cloudclassroom-php Project | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function. | |||||
| CVE-2024-57412 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets. | |||||
| CVE-2024-57409 | 1 Beian.miit | 1 Cool-admin-java | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field. | |||||
| CVE-2024-57408 | 1 Beian.miit | 1 Cool-admin-java | 2026-06-17 | N/A | 7.2 HIGH |
| An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-57407 | 2026-06-17 | N/A | 7.3 HIGH | ||
| An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-57401 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function. | |||||
| CVE-2024-57395 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters. | |||||
| CVE-2024-57394 | 1 Qianxin | 1 Tianqing Endpoint Security Management System | 2026-06-17 | N/A | 8.8 HIGH |
| The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities. | |||||
| CVE-2024-57392 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port. | |||||
| CVE-2024-57386 | 1 Wallosapp | 1 Wallos | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function. | |||||
| CVE-2024-57378 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources. | |||||
| CVE-2024-57376 | 1 Dlink | 12 Dsr-1000n, Dsr-1000n Firmware, Dsr-150 and 9 more | 2026-06-17 | N/A | 8.8 HIGH |
| Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution. | |||||
| CVE-2024-57375 | 2026-06-17 | N/A | 2.4 LOW | ||
| Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) via certain deselect actions. | |||||
| CVE-2024-57373 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise. | |||||
| CVE-2024-57372 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters | |||||
| CVE-2024-57369 | 1 Typecho | 1 Typecho | 2026-06-17 | N/A | 6.4 MEDIUM |
| Clickjacking vulnerability in typecho v1.2.1. | |||||
| CVE-2024-57360 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function. | |||||
