Vulnerabilities (CVE)

Total 396407 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37830 1 Getoutline 1 Outline 2026-06-17 N/A 6.1 MEDIUM
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
CVE-2024-37829 1 Getoutline 1 Outline 2026-06-17 N/A 8.8 HIGH
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.
CVE-2024-37828 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field under the Set Broadcast Message module.
CVE-2024-37826 1 Vercot 1 Serva 2026-06-17 N/A 7.5 HIGH
A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
CVE-2024-37825 2026-06-17 N/A 5.4 MEDIUM
An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network to perform a directory traversal.
CVE-2024-37820 2026-06-17 N/A 5.4 MEDIUM
A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.
CVE-2024-37818 1 Strapi 1 Strapi 2026-06-17 N/A 8.6 HIGH
Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or access sensitive information via a crafted GET request. NOTE: The Strapi Development Community argues that this issue is not valid. They contend that "the strapi/admin was wrongly attributed a flaw that only pertains to the strapi.io website, and which, at the end of the day, does not pose any real SSRF risk to applications that make use of the Strapi library."
CVE-2024-37803 1 Health Care Hospital Management System Project 1 Health Care Hospital Management System 2026-06-17 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
CVE-2024-37802 1 Health Care Hospital Management System Project 1 Health Care Hospital Management System 2026-06-17 N/A 8.8 HIGH
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.
CVE-2024-37800 1 Code-projects 1 Restaurant Reservation System 2026-06-17 N/A 6.1 MEDIUM
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.
CVE-2024-37799 1 Code-projects 1 Restaurant Reservation System 2026-06-17 N/A 5.4 MEDIUM
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.
CVE-2024-37798 1 Phpgurukul 1 Beauty Parlour Management System 2026-06-17 N/A 5.9 MEDIUM
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
CVE-2024-37795 2026-06-17 N/A 7.5 HIGH
A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` command with specific formatting errors.
CVE-2024-37794 2026-06-17 N/A 7.5 HIGH
Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.
CVE-2024-37791 2026-06-17 N/A 6.0 MEDIUM
DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.
CVE-2024-37783 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.
CVE-2024-37782 2026-06-17 N/A 9.8 CRITICAL
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.
CVE-2024-37779 2026-06-17 N/A 8.8 HIGH
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
CVE-2024-37777 1 Zoneland 1 O2oa 2026-06-17 N/A 8.8 HIGH
O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
CVE-2024-37770 1 B1ackc4t 1 14finger 2026-06-17 N/A 9.1 CRITICAL
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.