Total
395554 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57159 | 1 07fly | 1 07flycms | 2026-06-17 | N/A | 3.5 LOW |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html. | |||||
| CVE-2024-57157 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token. | |||||
| CVE-2024-57155 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token. | |||||
| CVE-2024-57154 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index. | |||||
| CVE-2024-57152 | 1 Winterchens | 1 My-site | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class | |||||
| CVE-2024-57151 | 1 Rockoa | 1 Xinhu | 2026-06-17 | N/A | 6.8 MEDIUM |
| SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function | |||||
| CVE-2024-57099 | 1 Classcms | 1 Classcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server. | |||||
| CVE-2024-57098 | 1 Deep-project | 1 Moss | 2026-06-17 | N/A | 9.8 CRITICAL |
| Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter. | |||||
| CVE-2024-57097 | 1 Classcms | 1 Classcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php. | |||||
| CVE-2024-57096 | 1 Kingsoft | 1 Wps Office | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file. | |||||
| CVE-2024-57095 | 1 Go-admin | 1 Go-cms | 2026-06-17 | N/A | 6.8 MEDIUM |
| SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload. | |||||
| CVE-2024-57086 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57085 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57084 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57083 | 1 Redocly | 1 Redoc | 2026-06-17 | N/A | 7.5 HIGH |
| A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57082 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57081 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57080 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57079 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
| CVE-2024-57078 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |||||
