Vulnerabilities (CVE)

Total 396407 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37769 1 B1ackc4t 1 14finger 2026-06-17 N/A 8.8 HIGH
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.
CVE-2024-37768 1 B1ackc4t 1 14finger 2026-06-17 N/A 9.1 CRITICAL
14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.
CVE-2024-37767 1 B1ackc4t 1 14finger 2026-06-17 N/A 7.5 HIGH
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.
CVE-2024-37765 1 Machform 1 Machform 2026-06-17 N/A 8.8 HIGH
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
CVE-2024-37764 1 Machform 1 Machform 2026-06-17 N/A 5.4 MEDIUM
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
CVE-2024-37763 1 Machform 1 Machform 2026-06-17 N/A 5.4 MEDIUM
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.
CVE-2024-37762 1 Machform 1 Machform 2026-06-17 N/A 9.9 CRITICAL
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
CVE-2024-37759 1 Datagear 1 Datagear 2026-06-17 N/A 9.8 CRITICAL
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.
CVE-2024-37758 2026-06-17 N/A 8.8 HIGH
Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.
CVE-2024-37743 1 Mmz-001 1 Knowledgegpt 2026-06-17 N/A 9.8 CRITICAL
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.
CVE-2024-37742 2026-06-17 N/A 8.2 HIGH
Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw, an attacker can bypass exam controls and gain an unfair advantage during exams.
CVE-2024-37741 1 Openplcproject 2 Openplc V3, Openplc V3 Firmware 2026-06-17 N/A 5.4 MEDIUM
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
CVE-2024-37734 1 Open-emr 1 Openemr 2026-06-17 N/A 9.8 CRITICAL
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
CVE-2024-37732 1 Anchorcms 1 Anchor Cms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
CVE-2024-37728 2026-06-17 N/A 7.5 HIGH
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface
CVE-2024-37726 2026-06-17 N/A 6.8 MEDIUM
Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe
CVE-2024-37699 2026-06-17 N/A 9.8 CRITICAL
An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.
CVE-2024-37681 2026-06-17 N/A 6.5 MEDIUM
An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of service via the index.html component.
CVE-2024-37680 1 Finesoft Project 1 Finesoft 2026-06-17 N/A 6.1 MEDIUM
Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows remote attackers to execute arbitrary code. Enter any account and password, click Login, the page will report an error, and a controllable parameter will appear at the URL:weburl.
CVE-2024-37679 1 Finesoft Project 1 Finesoft 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp parameter.