Vulnerabilities (CVE)

Total 395086 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-53459 1 Sysax 1 Multi Server 2026-06-17 N/A 5.4 MEDIUM
Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.
CVE-2024-53458 1 Sysax 1 Multi Server 2026-06-17 N/A 7.5 HIGH
Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.
CVE-2024-53457 1 Librenms 1 Librenms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.
CVE-2024-53450 1 Infiniflow 1 Ragflow 2026-06-17 N/A 7.5 HIGH
RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.
CVE-2024-53442 2026-06-17 N/A 9.8 CRITICAL
whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.
CVE-2024-53441 2026-06-17 N/A 9.1 CRITICAL
An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.
CVE-2024-53438 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 9.8 CRITICAL
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.
CVE-2024-53432 2026-06-17 N/A 7.5 HIGH
While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to cause a denial-of-service (DoS) attack when processing untrusted PLY files.
CVE-2024-53429 2026-06-17 N/A 7.5 HIGH
Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
CVE-2024-53427 1 Jqlang 1 Jq 2026-06-17 N/A 8.1 HIGH
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input has a certain form of digit string with NaN (e.g., "1 NaN123" immediately followed by many more digits).
CVE-2024-53426 2026-06-17 N/A 6.2 MEDIUM
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-53425 1 Assimp 1 Assimp 2026-06-17 N/A 6.2 MEDIUM
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.
CVE-2024-53423 1 Opennetworking 1 Onos 2026-06-17 N/A 5.6 MEDIUM
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.
CVE-2024-53412 2026-06-17 N/A 8.4 HIGH
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field
CVE-2024-53408 2026-06-17 N/A 5.4 MEDIUM
AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-53407 1 Phiewer 1 Phiewer 2026-06-17 N/A 3.3 LOW
In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.
CVE-2024-53406 1 Espressif 1 Esp-idf 2026-06-17 N/A 8.8 HIGH
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.
CVE-2024-53388 1 Mavo 1 Mavo 2026-06-17 N/A 8.8 HIGH
A DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML element.
CVE-2024-53387 1 Umeditor Project 1 Umeditor 2026-06-17 N/A 8.8 HIGH
A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.
CVE-2024-53386 1 Piqnt 1 Stage.js 2026-06-17 N/A 4.9 MEDIUM
Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.