Total
396611 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-34549 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2. | |||||
| CVE-2024-34548 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.4.8. | |||||
| CVE-2024-34547 | 1 Wpthemespace | 1 Magical Addons For Elementor | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34. | |||||
| CVE-2024-34546 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Sticky Social Link sticky-social-link allows DOM-Based XSS.This issue affects Sticky Social Link: from n/a through <= 2.0.1. | |||||
| CVE-2024-34545 | 1 Intel | 1 Raid Web Console | 2026-06-17 | N/A | 5.2 MEDIUM |
| Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access. | |||||
| CVE-2024-34544 | 1 Wavlink | 2 Wl-wn533a8, Wl-wn533a8 Firmware | 2026-06-17 | N/A | 9.1 CRITICAL |
| A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |||||
| CVE-2024-34543 | 1 Intel | 1 Raid Web Console | 2026-06-17 | N/A | 6.7 MEDIUM |
| Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |||||
| CVE-2024-34542 | 1 Advantech | 2 Adam-5630, Adam-5630 Firmware | 2026-06-17 | N/A | 5.7 MEDIUM |
| Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process. | |||||
| CVE-2024-34539 | 2026-06-17 | N/A | 9.4 CRITICAL | ||
| Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged actions. | |||||
| CVE-2024-34538 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography. | |||||
| CVE-2024-34537 | 1 Typo3 | 1 Typo3 | 2026-06-17 | N/A | 4.9 MEDIUM |
| TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1. | |||||
| CVE-2024-34535 | 1 Joinmastodon | 1 Mastodon | 2026-06-17 | N/A | 5.9 MEDIUM |
| In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header. | |||||
| CVE-2024-34534 | 2026-06-17 | N/A | 7.3 HIGH | ||
| A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model. | |||||
| CVE-2024-34533 | 2026-06-17 | N/A | 7.3 HIGH | ||
| A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZITools::query_fetch, or IZITools::query_execute. | |||||
| CVE-2024-34532 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query. | |||||
| CVE-2024-34529 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| Nebari through 2024.4.1 prints the temporary Keycloak root password. | |||||
| CVE-2024-34528 | 2026-06-17 | N/A | 7.7 HIGH | ||
| WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation. | |||||
| CVE-2024-34527 | 2026-06-17 | N/A | 7.5 HIGH | ||
| spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged. | |||||
| CVE-2024-34525 | 1 Lanol | 1 Filecodebox | 2026-06-17 | N/A | 5.3 MEDIUM |
| FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file. | |||||
| CVE-2024-34524 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content. | |||||
