Vulnerabilities (CVE)

Total 395947 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-41435 1 Yugabyte 1 Yugabytedb 2026-06-17 N/A 7.5 HIGH
YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
CVE-2024-41434 1 Pingcap 1 Tidb 2026-06-17 N/A 4.3 MEDIUM
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type. NOTE: PingCAP disputes this, arguing that reproduction did not cause the security impact of service interruption to other users. They maintain it is a complex query bug in the product but not a DoS.
CVE-2024-41433 1 Pingcap 1 Tidb 2026-06-17 N/A 9.8 CRITICAL
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reproduction of this issue did not cause the security impact of service interruption to other users. They argue that this is a complex query bug and not a DoS vulnerability.
CVE-2024-41432 1 Likeshop 1 Likeshop 2026-06-17 N/A 5.3 MEDIUM
An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.
CVE-2024-41381 1 Microweber 1 Microweber 2026-06-17 N/A 6.1 MEDIUM
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
CVE-2024-41380 1 Microweber 1 Microweber 2026-06-17 N/A 6.1 MEDIUM
microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
CVE-2024-41376 1 Dzzoffice 1 Dzzoffice 2026-06-17 N/A 8.8 HIGH
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
CVE-2024-41375 1 Icecoder 1 Icecoder 2026-06-17 N/A 6.1 MEDIUM
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
CVE-2024-41374 1 Icecoder 1 Icecoder 2026-06-17 N/A 6.1 MEDIUM
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
CVE-2024-41373 1 Icecoder 1 Icecoder 2026-06-17 N/A 6.3 MEDIUM
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
CVE-2024-41372 1 Organizr 1 Organizr 2026-06-17 N/A 9.8 CRITICAL
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.
CVE-2024-41371 1 Organizr 1 Organizr 2026-06-17 N/A 6.1 MEDIUM
Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
CVE-2024-41370 1 Organizr 1 Organizr 2026-06-17 N/A 9.8 CRITICAL
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
CVE-2024-41369 1 Sourcefabric 1 Phoniebox 2026-06-17 N/A 9.8 CRITICAL
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php
CVE-2024-41368 1 Sourcefabric 1 Phoniebox 2026-06-17 N/A 9.8 CRITICAL
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php
CVE-2024-41367 1 Sourcefabric 1 Phoniebox 2026-06-17 N/A 9.8 CRITICAL
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php
CVE-2024-41366 1 Sourcefabric 1 Phoniebox 2026-06-17 N/A 9.8 CRITICAL
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
CVE-2024-41364 1 Sourcefabric 1 Phoniebox 2026-06-17 N/A 9.8 CRITICAL
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
CVE-2024-41361 1 Sourcefabric 1 Phoniebox 2026-06-17 N/A 9.8 CRITICAL
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php
CVE-2024-41358 1 Phpipam 1 Phpipam 2026-06-17 N/A 6.1 MEDIUM
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.