Total
396474 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-36399 | 1 Kanboard | 1 Kanboard | 2026-06-17 | N/A | 8.2 HIGH |
| Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the request gets processed. The users permission for the POST BODY parameter project_id does not get checked again while processing. An attacker with the 'Project Manager' on a single project may take over any other project. The vulnerability is fixed in 1.2.37. | |||||
| CVE-2024-36398 | 1 Siemens | 1 Sinec Nms | 2026-06-17 | N/A | 7.8 HIGH |
| A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges. | |||||
| CVE-2024-36397 | 1 Vantiva | 2 Mediaaccess Dga2232, Mediaaccess Dga2232 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-36396 | 1 Verint | 1 Workforce Optimization | 2026-06-17 | N/A | 8.8 HIGH |
| Verint - CWE-434: Unrestricted Upload of File with Dangerous Type | |||||
| CVE-2024-36395 | 1 Verint | 1 Workforce Optimization | 2026-06-17 | N/A | 6.1 MEDIUM |
| Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | |||||
| CVE-2024-36394 | 1 Sysaid | 1 Sysaid | 2026-06-17 | N/A | 9.1 CRITICAL |
| SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |||||
| CVE-2024-36393 | 1 Sysaid | 1 Sysaid | 2026-06-17 | N/A | 9.9 CRITICAL |
| SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |||||
| CVE-2024-36392 | 2 Canonical, Milesight | 2 Ubuntu Linux, Devicehub | 2026-06-17 | N/A | 6.1 MEDIUM |
| MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-36391 | 2 Canonical, Milesight | 2 Ubuntu Linux, Devicehub | 2026-06-17 | N/A | 9.1 CRITICAL |
| MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic | |||||
| CVE-2024-36390 | 2 Canonical, Milesight | 2 Ubuntu Linux, Devicehub | 2026-06-17 | N/A | 7.5 HIGH |
| MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service | |||||
| CVE-2024-36389 | 2 Canonical, Milesight | 2 Ubuntu Linux, Devicehub | 2026-06-17 | N/A | 9.8 CRITICAL |
| MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass | |||||
| CVE-2024-36388 | 2 Canonical, Milesight | 2 Ubuntu Linux, Devicehub | 2026-06-17 | N/A | 10.0 CRITICAL |
| MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function | |||||
| CVE-2024-36387 | 2 Apache, Netapp | 2 Http Server, Ontap | 2026-06-17 | N/A | 5.4 MEDIUM |
| Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. | |||||
| CVE-2024-36384 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages. | |||||
| CVE-2024-36383 | 1 Logpoint | 1 Saml Authentication | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage. | |||||
| CVE-2024-36378 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.9 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens | |||||
| CVE-2024-36377 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 6.5 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions | |||||
| CVE-2024-36376 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 6.5 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions | |||||
| CVE-2024-36375 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.3 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed | |||||
| CVE-2024-36374 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible | |||||
