Vulnerabilities (CVE)

Total 396026 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39072 1 Amttgroup 1 Hibos 2026-06-17 N/A 5.5 MEDIUM
AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calendar_remind.php.
CVE-2024-39071 2026-06-17 N/A 9.8 CRITICAL
Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
CVE-2024-39069 2026-06-17 N/A 7.8 HIGH
An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.
CVE-2024-39063 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 8.8 HIGH
Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.
CVE-2024-39037 1 Airc 1 Mynet 2026-06-17 N/A 6.5 MEDIUM
MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu parameter.
CVE-2024-39036 1 Seacms 1 Seacms 2026-06-17 N/A 6.5 MEDIUM
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
CVE-2024-39033 2026-06-17 N/A 7.5 HIGH
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.
CVE-2024-39031 1 Silverpeas 1 Silverpeas 2026-06-17 N/A 5.4 MEDIUM
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event.
CVE-2024-39028 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
CVE-2024-39027 1 Seacms 1 Seacms 2026-06-17 N/A 7.5 HIGH
SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause sensitive database information to be leaked.
CVE-2024-39025 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
CVE-2024-39023 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close
CVE-2024-39022 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal
CVE-2024-39021 1 Idccms 1 Idccms 2026-06-17 N/A 5.4 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?mudi=del
CVE-2024-39020 1 Idccms 1 Idccms 2026-06-17 N/A 6.3 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?mudi=rev&nohrefStr=close
CVE-2024-39019 1 Idccms 1 Idccms 2026-06-17 N/A 5.4 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?mudi=del
CVE-2024-39018 2026-06-17 N/A 6.3 MEDIUM
harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVE-2024-39017 2026-06-17 N/A 9.8 CRITICAL
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVE-2024-39016 2026-06-17 N/A 8.1 HIGH
che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVE-2024-39015 2026-06-17 N/A 9.8 CRITICAL
cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.