Vulnerabilities (CVE)

Total 395466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-55539 2026-06-17 N/A 2.5 LOW
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, Acronis Cyber Protect 16 (Linux) before build 39938.
CVE-2024-55538 2026-06-17 N/A 4.0 MEDIUM
Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736, Acronis True Image OEM (macOS) before build 42571, Acronis True Image OEM (Windows) before build 42575.
CVE-2024-55532 1 Apache 1 Ranger 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.
CVE-2024-55529 1 Zblogcn 1 Z-blogphp 2026-06-17 N/A 9.8 CRITICAL
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
CVE-2024-55517 2026-06-17 N/A 8.8 HIGH
An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session.
CVE-2024-55516 1 Raisecom 8 Msg1200, Msg1200 Firmware, Msg2100e and 5 more 2026-06-17 N/A 9.1 CRITICAL
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
CVE-2024-55515 1 Raisecom 8 Msg1200, Msg1200 Firmware, Msg2100e and 5 more 2026-06-17 N/A 9.8 CRITICAL
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.
CVE-2024-55514 1 Raisecom 8 Msg1200, Msg1200 Firmware, Msg2100e and 5 more 2026-06-17 N/A 6.3 MEDIUM
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
CVE-2024-55513 1 Raisecom 8 Msg1200, Msg1200 Firmware, Msg2100e and 5 more 2026-06-17 N/A 9.1 CRITICAL
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
CVE-2024-55511 2026-06-17 N/A 7.8 HIGH
A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or potentially elevate their privileges via executing a specially crafted executable.
CVE-2024-55509 1 Codeastro 1 Complaint Management System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
CVE-2024-55507 1 Codeastro 1 Complaint Management System 2026-06-17 N/A 9.8 CRITICAL
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
CVE-2024-55506 1 Codeastro 1 Complaint Management System 2026-06-17 N/A 8.8 HIGH
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.
CVE-2024-55505 1 Codeastro 1 Complaint Management System 2026-06-17 N/A 8.8 HIGH
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.
CVE-2024-55504 2026-06-17 N/A 5.5 MEDIUM
An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.
CVE-2024-55503 2 Apple, Termius 2 Macos, Termius 2026-06-17 N/A 3.3 LOW
An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES component.
CVE-2024-55500 2026-06-17 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine.
CVE-2024-55496 1 1000projects 1 Bookstore Management System 2026-06-17 N/A 9.1 CRITICAL
A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.
CVE-2024-55494 2026-06-17 N/A 6.1 MEDIUM
A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.
CVE-2024-55492 1 Magicwinmail 1 Winmail Server 2026-06-17 N/A 6.1 MEDIUM
Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).