Total
396574 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-35112 | 1 Ibm | 1 Control Center | 2026-06-17 | N/A | 5.4 MEDIUM |
| IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |||||
| CVE-2024-35111 | 1 Ibm | 1 Control Center | 2026-06-17 | N/A | 4.3 MEDIUM |
| IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |||||
| CVE-2024-35110 | 1 Yzmcms | 1 Yzmcms | 2026-06-17 | N/A | 5.5 MEDIUM |
| A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker. | |||||
| CVE-2024-35109 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 6.5 MEDIUM |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close. | |||||
| CVE-2024-35108 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.8 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&dataType=&dataTypeCN. | |||||
| CVE-2024-35106 | 2026-06-17 | N/A | 4.6 MEDIUM | ||
| NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request. | |||||
| CVE-2024-35102 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script. | |||||
| CVE-2024-35099 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth. | |||||
| CVE-2024-35091 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 9.8 CRITICAL |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml. | |||||
| CVE-2024-35090 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 8.2 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml. | |||||
| CVE-2024-35086 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 9.8 CRITICAL |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml . | |||||
| CVE-2024-35085 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 5.4 MEDIUM |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml. | |||||
| CVE-2024-35084 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 9.8 CRITICAL |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml. | |||||
| CVE-2024-35083 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 8.8 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml. | |||||
| CVE-2024-35082 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 6.3 MEDIUM |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml. | |||||
| CVE-2024-35081 | 1 Luckyframe | 1 Luckyframeweb | 2026-06-17 | N/A | 7.5 HIGH |
| LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method. | |||||
| CVE-2024-35080 | 1 Inxedu | 1 Inxedu | 2026-06-17 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file. | |||||
| CVE-2024-35079 | 1 Inxedu | 1 Inxedu | 2026-06-17 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file. | |||||
| CVE-2024-35061 | 1 Nasa | 1 Ait Core | 2026-06-17 | N/A | 7.3 HIGH |
| NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution. | |||||
| CVE-2024-35060 | 1 Nasa | 1 Ait Core | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file. | |||||
