Vulnerabilities (CVE)

Total 395554 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57159 1 07fly 1 07flycms 2026-06-17 N/A 3.5 LOW
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.
CVE-2024-57157 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.
CVE-2024-57155 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.
CVE-2024-57154 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.
CVE-2024-57152 1 Winterchens 1 My-site 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class
CVE-2024-57151 1 Rockoa 1 Xinhu 2026-06-17 N/A 6.8 MEDIUM
SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function
CVE-2024-57099 1 Classcms 1 Classcms 2026-06-17 N/A 9.8 CRITICAL
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.
CVE-2024-57098 1 Deep-project 1 Moss 2026-06-17 N/A 9.8 CRITICAL
Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.
CVE-2024-57097 1 Classcms 1 Classcms 2026-06-17 N/A 4.8 MEDIUM
ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
CVE-2024-57096 1 Kingsoft 1 Wps Office 2026-06-17 N/A 5.5 MEDIUM
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
CVE-2024-57095 1 Go-admin 1 Go-cms 2026-06-17 N/A 6.8 MEDIUM
SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-57086 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57085 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57084 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57083 1 Redocly 1 Redoc 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57082 2026-06-17 N/A 6.5 MEDIUM
A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57081 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57080 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57079 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVE-2024-57078 2026-06-17 N/A 7.5 HIGH
A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.