Vulnerabilities (CVE)

Total 395466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-55214 1 Dhtmlx 1 File Explorer 2026-06-17 N/A 6.5 MEDIUM
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.
CVE-2024-55213 1 Dhtmlx 1 File Explorer 2026-06-17 N/A 6.5 MEDIUM
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.
CVE-2024-55212 2026-06-17 N/A 6.5 MEDIUM
DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.
CVE-2024-55211 1 Think 2 Tk-rt-wr135g, Tk-rt-wr135g Firmware 2026-06-17 N/A 8.4 HIGH
An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
CVE-2024-55210 1 Totvs 1 Framework \(linha Protheus\) 2026-06-17 N/A 9.8 CRITICAL
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.
CVE-2024-55199 1 Celk 1 Celk Saude 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
CVE-2024-55198 1 Celk 1 Celk Saude 2026-06-17 N/A 5.3 MEDIUM
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
CVE-2024-55196 2026-06-17 N/A 7.5 HIGH
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
CVE-2024-55195 2026-06-17 N/A 7.5 HIGH
An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requests to allocate too much space.
CVE-2024-55194 1 Openimageio 1 Openimageio 2026-06-17 N/A 9.8 CRITICAL
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
CVE-2024-55193 1 Openimageio 1 Openimageio 2026-06-17 N/A 9.8 CRITICAL
OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
CVE-2024-55192 1 Openimageio 1 Openimageio 2026-06-17 N/A 9.8 CRITICAL
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
CVE-2024-55186 2026-06-17 N/A 4.3 MEDIUM
An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users.
CVE-2024-55159 2026-06-17 N/A 4.2 MEDIUM
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.
CVE-2024-55156 2026-06-17 N/A 5.5 MEDIUM
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
CVE-2024-55104 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.
CVE-2024-55103 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.
CVE-2024-55100 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter.
CVE-2024-55099 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.
CVE-2024-55093 1 Phpipam 1 Phpipam 2026-06-17 N/A 5.4 MEDIUM
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.