Total
396407 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-37769 | 1 B1ackc4t | 1 14finger | 2026-06-17 | N/A | 8.8 HIGH |
| Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request. | |||||
| CVE-2024-37768 | 1 B1ackc4t | 1 14finger | 2026-06-17 | N/A | 9.1 CRITICAL |
| 14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id. | |||||
| CVE-2024-37767 | 1 B1ackc4t | 1 14finger | 2026-06-17 | N/A | 7.5 HIGH |
| Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request. | |||||
| CVE-2024-37765 | 1 Machform | 1 Machform | 2026-06-17 | N/A | 8.8 HIGH |
| Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page. | |||||
| CVE-2024-37764 | 1 Machform | 1 Machform | 2026-06-17 | N/A | 5.4 MEDIUM |
| MachForm up to version 19 is affected by an authenticated stored cross-site scripting. | |||||
| CVE-2024-37763 | 1 Machform | 1 Machform | 2026-06-17 | N/A | 5.4 MEDIUM |
| MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results. | |||||
| CVE-2024-37762 | 1 Machform | 1 Machform | 2026-06-17 | N/A | 9.9 CRITICAL |
| MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution. | |||||
| CVE-2024-37759 | 1 Datagear | 1 Datagear | 2026-06-17 | N/A | 9.8 CRITICAL |
| DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface. | |||||
| CVE-2024-37758 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges. | |||||
| CVE-2024-37743 | 1 Mmz-001 | 1 Knowledgegpt | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component. | |||||
| CVE-2024-37742 | 2026-06-17 | N/A | 8.2 HIGH | ||
| Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams. | |||||
| CVE-2024-37741 | 1 Openplcproject | 2 Openplc V3, Openplc V3 Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture. | |||||
| CVE-2024-37734 | 1 Open-emr | 1 Openemr | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter. | |||||
| CVE-2024-37732 | 1 Anchorcms | 1 Anchor Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file. | |||||
| CVE-2024-37728 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface | |||||
| CVE-2024-37726 | 2026-06-17 | N/A | 6.8 MEDIUM | ||
| Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe | |||||
| CVE-2024-37699 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption. | |||||
| CVE-2024-37681 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of service via the index.html component. | |||||
| CVE-2024-37680 | 1 Finesoft Project | 1 Finesoft | 2026-06-17 | N/A | 6.1 MEDIUM |
| Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows remote attackers to execute arbitrary code. Enter any account and password, click Login, the page will report an error, and a controllable parameter will appear at the URL:weburl. | |||||
| CVE-2024-37679 | 1 Finesoft Project | 1 Finesoft | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp parameter. | |||||
