Total
395466 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-55354 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failure that can let an attacker run code that would be expected to be blocked and access resources that would be expected to be protected. | |||||
| CVE-2024-55342 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-06-17 | N/A | 4.7 MEDIUM |
| A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability. | |||||
| CVE-2024-55341 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-06-17 | N/A | 4.7 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload. | |||||
| CVE-2024-55279 | 1 Uguu | 1 Uguu | 2026-06-17 | N/A | 6.0 MEDIUM |
| Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files. | |||||
| CVE-2024-55272 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function. | |||||
| CVE-2024-55271 | 1 Phpgurukul | 1 Gym Management System | 2026-06-17 | N/A | 3.5 LOW |
| A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint. | |||||
| CVE-2024-55270 | 1 Phpgurukul | 1 Student Management System | 2026-06-17 | N/A | 8.8 HIGH |
| phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter. | |||||
| CVE-2024-55268 | 1 Phpgurukul | 1 Covid 19 Testing Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute arbitrary code via the regmobilenumber parameter. | |||||
| CVE-2024-55241 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component. | |||||
| CVE-2024-55239 | 1 Portabilis | 1 I-educar | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter. | |||||
| CVE-2024-55238 | 1 Open-metadata | 1 Openmetadata | 2026-06-17 | N/A | 7.1 HIGH |
| OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query. | |||||
| CVE-2024-55232 | 1 Phpgurukul | 1 Online Notes Sharing Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information. | |||||
| CVE-2024-55231 | 1 Phpgurukul | 1 Online Notes Sharing Management System | 2026-06-17 | N/A | 4.3 MEDIUM |
| An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information. | |||||
| CVE-2024-55228 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.0 CRITICAL |
| A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-55227 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.0 CRITICAL |
| A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-55226 | 1 Dani-garcia | 1 Vaultwarden | 2026-06-17 | N/A | 5.4 MEDIUM |
| Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs. | |||||
| CVE-2024-55225 | 1 Dani-garcia | 1 Vaultwarden | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request. | |||||
| CVE-2024-55224 | 1 Dani-garcia | 1 Vaultwarden | 2026-06-17 | N/A | 9.6 CRITICAL |
| An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message. | |||||
| CVE-2024-55218 | 1 Icewarp | 1 Icewarp | 2026-06-17 | N/A | 6.1 MEDIUM |
| IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter. | |||||
| CVE-2024-55215 | 1 Jrohy | 1 Trojan | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register. | |||||
