Total
395466 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-55471 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter. | |||||
| CVE-2024-55470 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or access restricted data without proper authorization. The lack of server-side validation exacerbates the issue, as the application relies on client-side information for authentication. | |||||
| CVE-2024-55466 | 1 Thingsboard | 1 Thingsboard | 2026-06-17 | N/A | 6.5 MEDIUM |
| An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-55461 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext(). | |||||
| CVE-2024-55460 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input. | |||||
| CVE-2024-55459 | 1 Keras | 1 Keras | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function. | |||||
| CVE-2024-55457 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially exposing sensitive information. | |||||
| CVE-2024-55456 | 1 Sammycage | 1 Lunasvg | 2026-06-17 | N/A | 6.5 MEDIUM |
| lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell | |||||
| CVE-2024-55452 | 1 Ujcms | 1 Ujcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage. | |||||
| CVE-2024-55451 | 1 Ujcms | 1 Ujcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens. | |||||
| CVE-2024-55417 | 1 Thecontrolgroup | 1 Voyager | 2026-06-17 | N/A | 4.3 MEDIUM |
| DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server. | |||||
| CVE-2024-55416 | 1 Thecontrolgroup | 1 Voyager | 2026-06-17 | N/A | 3.5 LOW |
| DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed. | |||||
| CVE-2024-55415 | 1 Thecontrolgroup | 1 Voyager | 2026-06-17 | N/A | 5.7 MEDIUM |
| DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass. | |||||
| CVE-2024-55414 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code. | |||||
| CVE-2024-55413 | 2026-06-17 | N/A | 7.8 HIGH | ||
| A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code. | |||||
| CVE-2024-55412 | 2026-06-17 | N/A | 7.8 HIGH | ||
| A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code. | |||||
| CVE-2024-55411 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests. | |||||
| CVE-2024-55408 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafted IOCTL requests are supplied. | |||||
| CVE-2024-55372 | 1 Wallosapp | 1 Wallos | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands. | |||||
| CVE-2024-55371 | 1 Wallosapp | 1 Wallos | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands. | |||||
