Vulnerabilities (CVE)

Total 396026 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39153 1 Idccms 1 Idccms 2026-06-17 N/A 4.7 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.
CVE-2024-39150 1 B3log 1 Vditor 2026-06-17 N/A 5.9 MEDIUM
vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.
CVE-2024-39148 1 Kerlink 1 Keros 2026-06-17 N/A 8.1 HIGH
The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.
CVE-2024-39143 1 Coderberg 1 Residencecms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload.
CVE-2024-39134 1 Gdraheim 1 Zziplib 2026-06-17 N/A 7.5 HIGH
A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.
CVE-2024-39133 1 Zziplib Project 1 Zziplib 2026-06-17 N/A 4.3 MEDIUM
Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c.
CVE-2024-39132 2026-06-17 N/A 6.5 MEDIUM
A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommandLine() at /src/DumpTS.cpp.
CVE-2024-39130 2026-06-17 N/A 7.5 HIGH
A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream() at /src/DumpStream.cpp.
CVE-2024-39129 2026-06-17 N/A 5.3 MEDIUM
Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function PushTSBuf() at /src/PayloadBuf.cpp.
CVE-2024-39126 1 Roundup-tracker 1 Roundup 2026-06-17 N/A 5.4 MEDIUM
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
CVE-2024-39125 1 Roundup-tracker 1 Roundup 2026-06-17 N/A 5.4 MEDIUM
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
CVE-2024-39124 1 Roundup-tracker 1 Roundup 2026-06-17 N/A 5.4 MEDIUM
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
CVE-2024-39123 1 Janeczku 1 Calibre-web 2026-06-17 N/A 5.4 MEDIUM
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.
CVE-2024-39119 1 Idccms 1 Idccms 2026-06-17 N/A 5.4 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.
CVE-2024-39118 1 Mommyheather 1 Advanced Backups 2026-06-17 N/A 5.5 MEDIUM
Mommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up.
CVE-2024-39097 1 Sir 1 Gnuboard 2026-06-17 N/A 6.1 MEDIUM
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
CVE-2024-39094 1 Friendica 1 Friendica 2026-06-17 N/A 5.4 MEDIUM
Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.
CVE-2024-39091 1 Annke 2 Crater 2, Crater 2 Firmware 2026-06-17 N/A 8.8 HIGH
An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.
CVE-2024-39090 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 6.1 MEDIUM
The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentially leading to account takeover.
CVE-2024-39081 1 Jktyre 1 Smart Tyre Car \& Bike 2026-06-17 N/A 4.2 MEDIUM
An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.