Vulnerabilities (CVE)

Total 395535 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-56365 1 Phpoffice 1 Phpspreadsheet 2026-06-17 N/A 5.4 MEDIUM
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/phpoffice/phpspreadsheet/samples/download.php` script, an attacker can perform a cross-site scripting attack. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.
CVE-2024-56364 2026-06-17 N/A 5.4 MEDIUM
SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13.
CVE-2024-56363 2026-06-17 N/A 7.8 HIGH
APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically, when user input is improperly sanitized or validated, an attacker can inject Jinja2 syntax into the template, causing the server to execute arbitrary code. For example, an attacker might be able to inject expressions like {{ config }}, {{ self.class.mro[1].subclasses() }}, or more dangerous payloads that trigger execution of arbitrary Python code. The vulnerability can be reproduced by submitting crafted input to all the template fields handled by ckeditor, that are passed directly to a Jinja2 template. If the input is rendered without sufficient sanitization, it results in the execution of malicious Jinja2 code on the server.
CVE-2024-56362 1 Navidrome 1 Navidrome 2026-06-17 N/A 7.1 HIGH
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1.
CVE-2024-56361 2026-06-17 N/A N/A
LGSL (Live Game Server List) provides online status for games. Before 7.0.0, a stored cross-site scripting (XSS) vulnerability was identified in lgsl. The function lgsl_query_40 in lgsl_protocol.php has implemented an HTTP crawler. This function makes a request to the registered game server, and upon crawling the malicious /info endpoint with our payload, will render our javascript on the info page. This information is being displayed via lgsl_details.php. This vulnerability is fixed in 7.0.0.
CVE-2024-56359 1 Getgrist 1 Grist-core 2026-06-17 N/A 8.1 HIGH
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click) could have their account compromised, since the link could use the javascript: scheme and be evaluated in the context of their current page. This issue has been patched in version 1.3.2. Users are advised to upgrade. Users unable to upgrade should avoid clicking on HyperLink cell links using a control modifier in documents prepared by people they do not trust.
CVE-2024-56358 1 Getgrist 1 Grist-core 2026-06-17 N/A 8.1 HIGH
grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluated in the context of their current page. This issue has been patched in version 1.3.2. Users are advised to upgrade. Users unable to upgrade should avoid previewing attachments in documents prepared by people they do not trust.
CVE-2024-56357 1 Getgrist 1 Grist-core 2026-06-17 N/A 8.1 HIGH
grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was possible to use the `javascript:` scheme with custom widget URLs and form redirect URLs. This issue has been patched in version 1.3.1. Users are advised to upgrade. Users unable to upgrade should avoid visiting documents or forms prepared by people they do not trust.
CVE-2024-56356 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.9 MEDIUM
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-56355 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
CVE-2024-56354 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
CVE-2024-56353 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-56352 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
CVE-2024-56351 1 Jetbrains 1 Teamcity 2026-06-17 N/A 6.3 MEDIUM
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
CVE-2024-56350 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
CVE-2024-56349 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2024-56348 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
CVE-2024-56347 1 Ibm 1 Aix 2026-06-17 N/A 9.6 CRITICAL
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
CVE-2024-56346 1 Ibm 1 Aix 2026-06-17 N/A 10.0 CRITICAL
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
CVE-2024-56343 1 Ibm 1 Verify Identity Access Digital Credentials 2026-06-17 N/A 4.3 MEDIUM
IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request.