Total
395535 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-56365 | 1 Phpoffice | 1 Phpspreadsheet | 2026-06-17 | N/A | 5.4 MEDIUM |
| PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/phpoffice/phpspreadsheet/samples/download.php` script, an attacker can perform a cross-site scripting attack. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue. | |||||
| CVE-2024-56364 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, when calling the extended toHTMLEx method, it is possible to execute arbitrary JavaScript code. This vulnerability is fixed in 1.1.13. | |||||
| CVE-2024-56363 | 2026-06-17 | N/A | 7.8 HIGH | ||
| APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically, when user input is improperly sanitized or validated, an attacker can inject Jinja2 syntax into the template, causing the server to execute arbitrary code. For example, an attacker might be able to inject expressions like {{ config }}, {{ self.class.mro[1].subclasses() }}, or more dangerous payloads that trigger execution of arbitrary Python code. The vulnerability can be reproduced by submitting crafted input to all the template fields handled by ckeditor, that are passed directly to a Jinja2 template. If the input is rendered without sufficient sanitization, it results in the execution of malicious Jinja2 code on the server. | |||||
| CVE-2024-56362 | 1 Navidrome | 1 Navidrome | 2026-06-17 | N/A | 7.1 HIGH |
| Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the property table. This practice introduces a security risk because anyone with access to the database file can retrieve the secret. This vulnerability is fixed in 0.54.1. | |||||
| CVE-2024-56361 | 2026-06-17 | N/A | N/A | ||
| LGSL (Live Game Server List) provides online status for games. Before 7.0.0, a stored cross-site scripting (XSS) vulnerability was identified in lgsl. The function lgsl_query_40 in lgsl_protocol.php has implemented an HTTP crawler. This function makes a request to the registered game server, and upon crawling the malicious /info endpoint with our payload, will render our javascript on the info page. This information is being displayed via lgsl_details.php. This vulnerability is fixed in 7.0.0. | |||||
| CVE-2024-56359 | 1 Getgrist | 1 Grist-core | 2026-06-17 | N/A | 8.1 HIGH |
| grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click) could have their account compromised, since the link could use the javascript: scheme and be evaluated in the context of their current page. This issue has been patched in version 1.3.2. Users are advised to upgrade. Users unable to upgrade should avoid clicking on HyperLink cell links using a control modifier in documents prepared by people they do not trust. | |||||
| CVE-2024-56358 | 1 Getgrist | 1 Grist-core | 2026-06-17 | N/A | 8.1 HIGH |
| grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluated in the context of their current page. This issue has been patched in version 1.3.2. Users are advised to upgrade. Users unable to upgrade should avoid previewing attachments in documents prepared by people they do not trust. | |||||
| CVE-2024-56357 | 1 Getgrist | 1 Grist-core | 2026-06-17 | N/A | 8.1 HIGH |
| grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was possible to use the `javascript:` scheme with custom widget URLs and form redirect URLs. This issue has been patched in version 1.3.1. Users are advised to upgrade. Users unable to upgrade should avoid visiting documents or forms prepared by people they do not trust. | |||||
| CVE-2024-56356 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.9 MEDIUM |
| In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | |||||
| CVE-2024-56355 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS | |||||
| CVE-2024-56354 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | |||||
| CVE-2024-56353 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies | |||||
| CVE-2024-56352 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page | |||||
| CVE-2024-56351 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 6.3 MEDIUM |
| In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | |||||
| CVE-2024-56350 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | |||||
| CVE-2024-56349 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.3 MEDIUM |
| In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | |||||
| CVE-2024-56348 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | |||||
| CVE-2024-56347 | 1 Ibm | 1 Aix | 2026-06-17 | N/A | 9.6 CRITICAL |
| IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls. | |||||
| CVE-2024-56346 | 1 Ibm | 1 Aix | 2026-06-17 | N/A | 10.0 CRITICAL |
| IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls. | |||||
| CVE-2024-56343 | 1 Ibm | 1 Verify Identity Access Digital Credentials | 2026-06-17 | N/A | 4.3 MEDIUM |
| IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request. | |||||
