Vulnerabilities (CVE)

Total 396138 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38470 1 Ibarn Project 1 Ibarn 2026-06-17 N/A 6.1 MEDIUM
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.
CVE-2024-38469 1 Ibarn Project 1 Ibarn 2026-06-17 N/A 6.3 MEDIUM
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.
CVE-2024-38468 1 Guoxinled 1 Synthesis Image System 2026-06-17 N/A 9.8 CRITICAL
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
CVE-2024-38467 1 Guoxinled 1 Synthesis Image System 2026-06-17 N/A 7.5 HIGH
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
CVE-2024-38466 1 Guoxinled 1 Synthesis Image System 2026-06-17 N/A 9.8 CRITICAL
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
CVE-2024-38465 1 Guoxinled 1 Synthesis Image System 2026-06-17 N/A 5.3 MEDIUM
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.
CVE-2024-38462 1 Irods 1 Irods 2026-06-17 N/A 9.8 CRITICAL
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
CVE-2024-38461 1 Irods 1 Irods 2026-06-17 N/A 7.5 HIGH
irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.
CVE-2024-38460 1 Sonarsource 1 Sonarqube 2026-06-17 N/A 4.9 MEDIUM
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
CVE-2024-38459 1 Langchain 1 Langchain-experimental 2026-06-17 N/A 7.8 HIGH
langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.
CVE-2024-38458 1 Xenforo 1 Xenforo 2026-06-17 N/A 8.8 HIGH
Xenforo before 2.2.16 allows code injection.
CVE-2024-38457 1 Xenforo 1 Xenforo 2026-06-17 N/A 8.8 HIGH
Xenforo before 2.2.16 allows CSRF.
CVE-2024-38456 2026-06-17 N/A 7.8 HIGH
HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM.
CVE-2024-38454 1 Expressionengine 1 Expressionengine 2026-06-17 N/A 6.1 MEDIUM
ExpressionEngine before 7.4.11 allows XSS.
CVE-2024-38453 2026-06-17 N/A 7.5 HIGH
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
CVE-2024-38449 2026-06-17 N/A 7.7 HIGH
A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.
CVE-2024-38448 2026-06-17 N/A 9.1 CRITICAL
htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.
CVE-2024-38447 1 Ncia 1 Advisor Network 2026-06-17 N/A 8.1 HIGH
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).
CVE-2024-38446 1 Ncia 1 Advisor Network 2026-06-17 N/A 6.5 MEDIUM
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in a POST request.
CVE-2024-38443 2026-06-17 N/A 6.2 MEDIUM
C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.