Total
396026 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-39153 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 4.7 MEDIUM |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN. | |||||
| CVE-2024-39150 | 1 B3log | 1 Vditor | 2026-06-17 | N/A | 5.9 MEDIUM |
| vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet. | |||||
| CVE-2024-39148 | 1 Kerlink | 1 Keros | 2026-06-17 | N/A | 8.1 HIGH |
| The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall. | |||||
| CVE-2024-39143 | 1 Coderberg | 1 Residencecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload. | |||||
| CVE-2024-39134 | 1 Gdraheim | 1 Zziplib | 2026-06-17 | N/A | 7.5 HIGH |
| A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c. | |||||
| CVE-2024-39133 | 1 Zziplib Project | 1 Zziplib | 2026-06-17 | N/A | 4.3 MEDIUM |
| Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c. | |||||
| CVE-2024-39132 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommandLine() at /src/DumpTS.cpp. | |||||
| CVE-2024-39130 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream() at /src/DumpStream.cpp. | |||||
| CVE-2024-39129 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function PushTSBuf() at /src/PayloadBuf.cpp. | |||||
| CVE-2024-39126 | 1 Roundup-tracker | 1 Roundup | 2026-06-17 | N/A | 5.4 MEDIUM |
| Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. | |||||
| CVE-2024-39125 | 1 Roundup-tracker | 1 Roundup | 2026-06-17 | N/A | 5.4 MEDIUM |
| Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header. | |||||
| CVE-2024-39124 | 1 Roundup-tracker | 1 Roundup | 2026-06-17 | N/A | 5.4 MEDIUM |
| In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS. | |||||
| CVE-2024-39123 | 1 Janeczku | 1 Calibre-web | 2026-06-17 | N/A | 5.4 MEDIUM |
| In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. | |||||
| CVE-2024-39119 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 5.4 MEDIUM |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close. | |||||
| CVE-2024-39118 | 1 Mommyheather | 1 Advanced Backups | 2026-06-17 | N/A | 5.5 MEDIUM |
| Mommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up. | |||||
| CVE-2024-39097 | 1 Sir | 1 Gnuboard | 2026-06-17 | N/A | 6.1 MEDIUM |
| There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. | |||||
| CVE-2024-39094 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 5.4 MEDIUM |
| Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters. | |||||
| CVE-2024-39091 | 1 Annke | 2 Crater 2, Crater 2 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request. | |||||
| CVE-2024-39090 | 1 Phpgurukul | 1 Online Shopping Portal | 2026-06-17 | N/A | 6.1 MEDIUM |
| The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to account takeover. | |||||
| CVE-2024-39081 | 1 Jktyre | 1 Smart Tyre Car \& Bike | 2026-06-17 | N/A | 4.2 MEDIUM |
| An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications. | |||||
