Total
395527 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48428 | 1 Olivegroup | 1 Olivevle | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function. | |||||
| CVE-2024-48427 | 1 Oretnom23 | 1 Packers And Movers Management System | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id | |||||
| CVE-2024-48426 | 1 Assimp | 1 Assimp | 2026-06-17 | N/A | 6.2 MEDIUM |
| A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). | |||||
| CVE-2024-48425 | 1 Assimp | 1 Assimp | 2026-06-17 | N/A | 5.5 MEDIUM |
| A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. | |||||
| CVE-2024-48424 | 1 Assimp | 1 Assimp | 2026-06-17 | N/A | 5.5 MEDIUM |
| A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. | |||||
| CVE-2024-48423 | 1 Assimp | 1 Assimp | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. | |||||
| CVE-2024-48415 | 1 Razormist | 1 Loan Management System | 2026-06-17 | N/A | 5.0 MEDIUM |
| itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page. | |||||
| CVE-2024-48411 | 1 Mayurik | 1 Online Tours \& Travels Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php. | |||||
| CVE-2024-48410 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php. | |||||
| CVE-2024-48406 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c. | |||||
| CVE-2024-48396 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts. | |||||
| CVE-2024-48394 | 2026-06-17 | N/A | 7.8 HIGH | ||
| A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. The vulnerability affects version 5.24.3 and before of the software. | |||||
| CVE-2024-48392 | 1 Orangescrum | 1 Orangescrum | 2026-06-17 | N/A | 5.4 MEDIUM |
| OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to lack of input validation, which could lead to account takeover. | |||||
| CVE-2024-48360 | 1 Qualitor | 1 Qualitor | 2026-06-17 | N/A | 7.5 HIGH |
| Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php. | |||||
| CVE-2024-48359 | 1 Qualitor | 1 Qualitor | 2026-06-17 | N/A | 9.8 CRITICAL |
| Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter. | |||||
| CVE-2024-48357 | 1 Lylme | 1 Lylme Spage | 2026-06-17 | N/A | 9.8 CRITICAL |
| LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php. | |||||
| CVE-2024-48356 | 1 Lylme | 1 Lylme Spage | 2026-06-17 | N/A | 9.8 CRITICAL |
| LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php. | |||||
| CVE-2024-48353 | 1 Yealink | 1 Yealink Meeting Server | 2026-06-17 | N/A | 7.5 HIGH |
| Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information. | |||||
| CVE-2024-48346 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems. | |||||
| CVE-2024-48343 | 1 Esafenet | 1 Cdg | 2026-06-17 | N/A | 6.3 MEDIUM |
| A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page. | |||||
