Vulnerabilities (CVE)

Total 395116 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-53620 1 Spip 1 Spip 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.
CVE-2024-53619 1 Spip 1 Spip 2026-06-17 N/A 6.3 MEDIUM
An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2024-53617 2026-06-17 N/A 4.8 MEDIUM
A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.
CVE-2024-53615 2026-06-17 N/A 6.5 MEDIUM
A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.
CVE-2024-53605 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.
CVE-2024-53604 1 Phpgurukul 1 Covid19 Testing Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.
CVE-2024-53603 1 Phpgurukul 1 Covid19 Testing Management System 2026-06-17 N/A 7.3 HIGH
A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.
CVE-2024-53599 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-53591 1 Seclore 1 Seclore 2026-06-17 N/A 9.8 CRITICAL
An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
CVE-2024-53589 2026-06-17 N/A 8.4 HIGH
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
CVE-2024-53588 2026-06-17 N/A 7.8 HIGH
A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6.
CVE-2024-53586 2026-06-17 N/A 5.3 MEDIUM
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.
CVE-2024-53584 1 Openpanel 1 Openpanel 2026-06-17 N/A 9.8 CRITICAL
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
CVE-2024-53582 1 Openpanel 1 Openpanel 2026-06-17 N/A 7.5 HIGH
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.
CVE-2024-53580 2 Es, Netapp 3 Iperf3, Hci Compute Node, Ontap 9 2026-06-17 N/A 7.5 HIGH
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
CVE-2024-53573 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 9.8 CRITICAL
Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.
CVE-2024-53569 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter.
CVE-2024-53568 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.
CVE-2024-53566 2 Debian, Sangoma 2 Debian Linux, Asterisk 2026-06-17 N/A 5.5 MEDIUM
An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.
CVE-2024-53564 1 Sangoma 1 Freepbx 2026-06-17 N/A 2.2 LOW
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what high-privilege administrators are intentionally allowed to do.