Vulnerabilities (CVE)

Total 396474 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36399 1 Kanboard 1 Kanboard 2026-06-17 N/A 8.2 HIGH
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37.
CVE-2024-36398 1 Siemens 1 Sinec Nms 2026-06-17 N/A 7.8 HIGH
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges.
CVE-2024-36397 1 Vantiva 2 Mediaaccess Dga2232, Mediaaccess Dga2232 Firmware 2026-06-17 N/A 6.1 MEDIUM
Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-36396 1 Verint 1 Workforce Optimization 2026-06-17 N/A 8.8 HIGH
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
CVE-2024-36395 1 Verint 1 Workforce Optimization 2026-06-17 N/A 6.1 MEDIUM
Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-36394 1 Sysaid 1 Sysaid 2026-06-17 N/A 9.1 CRITICAL
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-36393 1 Sysaid 1 Sysaid 2026-06-17 N/A 9.9 CRITICAL
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-36392 2 Canonical, Milesight 2 Ubuntu Linux, Devicehub 2026-06-17 N/A 6.1 MEDIUM
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-36391 2 Canonical, Milesight 2 Ubuntu Linux, Devicehub 2026-06-17 N/A 9.1 CRITICAL
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
CVE-2024-36390 2 Canonical, Milesight 2 Ubuntu Linux, Devicehub 2026-06-17 N/A 7.5 HIGH
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
CVE-2024-36389 2 Canonical, Milesight 2 Ubuntu Linux, Devicehub 2026-06-17 N/A 9.8 CRITICAL
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
CVE-2024-36388 2 Canonical, Milesight 2 Ubuntu Linux, Devicehub 2026-06-17 N/A 10.0 CRITICAL
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
CVE-2024-36387 2 Apache, Netapp 2 Http Server, Ontap 2026-06-17 N/A 5.4 MEDIUM
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
CVE-2024-36384 2026-06-17 N/A 6.1 MEDIUM
Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.
CVE-2024-36383 1 Logpoint 1 Saml Authentication 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage.
CVE-2024-36378 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.9 MEDIUM
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
CVE-2024-36377 1 Jetbrains 1 Teamcity 2026-06-17 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
CVE-2024-36376 1 Jetbrains 1 Teamcity 2026-06-17 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
CVE-2024-36375 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
CVE-2024-36374 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible