Vulnerabilities (CVE)

Total 395801 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42914 1 Arrowjs 1 Arrowcms 2026-06-17 N/A 9.1 CRITICAL
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords.
CVE-2024-42913 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 9.8 CRITICAL
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
CVE-2024-42912 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.
CVE-2024-42906 1 Testlink 1 Testlink 2026-06-17 N/A 6.1 MEDIUM
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.
CVE-2024-42905 2026-06-17 N/A 9.8 CRITICAL
Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.
CVE-2024-42904 1 Syspass 1 Syspass 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientController.php.
CVE-2024-42903 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 6.5 MEDIUM
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
CVE-2024-42902 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 8.8 HIGH
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function
CVE-2024-42901 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 4.8 MEDIUM
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.
CVE-2024-42900 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 6.1 MEDIUM
Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.
CVE-2024-42898 1 Nagios 1 Nagios Xi 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
CVE-2024-42885 1 Esafenet 1 Cdg 2026-06-17 N/A 9.1 CRITICAL
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
CVE-2024-42861 1 Linuxptp Project 1 Linuxptp 2026-06-17 N/A 7.5 HIGH
An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
CVE-2024-42852 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php component.
CVE-2024-42851 1 Aertherwide 1 Exiftags 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.
CVE-2024-42845 2026-06-17 N/A 8.0 HIGH
An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.
CVE-2024-42844 2026-06-17 N/A 8.1 HIGH
A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information
CVE-2024-42843 1 Projectworlds 1 Online Examination System 2026-06-17 N/A 9.8 CRITICAL
Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.
CVE-2024-42835 1 Langflow 1 Langflow 2026-06-17 N/A 9.8 CRITICAL
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
CVE-2024-42834 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter.