Vulnerabilities (CVE)

Total 396611 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-34480 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
CVE-2024-34479 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
CVE-2024-34478 1 Btcd Project 1 Btcd 2026-06-17 N/A 7.5 HIGH
btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptible to consensus failures. Specifically, it uses the transaction version as a signed integer when it is supposed to be treated as unsigned. There can be a chain split and loss of funds.
CVE-2024-34477 1 Fogproject 1 Fogproject 2026-06-17 N/A 7.8 HIGH
configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In order to exploit the vulnerability, someone needs to mount an NFS share in order to add an executable file as root. In addition, the SUID bit must be added to this file.
CVE-2024-34476 1 Open5gs 1 Open5gs 2026-06-17 N/A 5.3 MEDIUM
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
CVE-2024-34475 1 Open5gs 1 Open5gs 2026-06-17 N/A 7.5 HIGH
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
CVE-2024-34474 2026-06-17 N/A 7.8 HIGH
Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.
CVE-2024-34473 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.
CVE-2024-34472 1 Hsclabs 1 Mailinspector 2026-06-17 N/A 5.5 MEDIUM
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.
CVE-2024-34471 1 Hsclabs 1 Mailinspector 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.
CVE-2024-34470 1 Hsclabs 1 Mailinspector 2026-06-17 N/A 8.6 HIGH
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.
CVE-2024-34469 1 Rukovoditel 1 Rukovoditel 2026-06-17 N/A 7.1 HIGH
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
CVE-2024-34468 1 Rukovoditel 1 Rukovoditel 2026-06-17 N/A 6.1 MEDIUM
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.
CVE-2024-34467 1 Thinkphp 1 Thinkphp 2026-06-17 N/A 6.1 MEDIUM
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.
CVE-2024-34463 2026-06-17 N/A 5.1 MEDIUM
BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)
CVE-2024-34462 1 Alinto 1 Sogo 2026-06-17 N/A 6.1 MEDIUM
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
CVE-2024-34461 2026-06-17 N/A 9.8 CRITICAL
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
CVE-2024-34460 2026-06-17 N/A 6.5 MEDIUM
The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)
CVE-2024-34459 1 Xmlsoft 1 Libxml2 2026-06-17 N/A 7.5 HIGH
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.
CVE-2024-34458 1 Keyfactor 1 Command 2026-06-17 N/A 7.5 HIGH
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.