Total
396633 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-34313 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint. | |||||
| CVE-2024-34312 | 1 Moodle | 1 Virtual Programming Lab | 2026-06-17 | N/A | 6.1 MEDIUM |
| Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js. | |||||
| CVE-2024-34310 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter. | |||||
| CVE-2024-34308 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode. | |||||
| CVE-2024-34274 | 2026-06-17 | N/A | 3.9 LOW | ||
| OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2024-34273 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method. | |||||
| CVE-2024-34257 | 1 Totolink | 2 Ex1800t, Ex1800t Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges. | |||||
| CVE-2024-34256 | 1 Ofcms Project | 1 Ofcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | |||||
| CVE-2024-34255 | 1 Jizhicms | 1 Jizhicms | 2026-06-17 | N/A | 6.1 MEDIUM |
| jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function. | |||||
| CVE-2024-34252 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 7.5 HIGH |
| wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c. | |||||
| CVE-2024-34251 | 1 Bytecodealliance | 1 Webassembly Micro Runtime | 2026-06-17 | N/A | 7.5 HIGH |
| An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | |||||
| CVE-2024-34250 | 1 Bytecodealliance | 1 Webassembly Micro Runtime | 2026-06-17 | N/A | 6.2 MEDIUM |
| A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c. | |||||
| CVE-2024-34249 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 9.8 CRITICAL |
| wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c. | |||||
| CVE-2024-34246 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 7.5 HIGH |
| wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c. | |||||
| CVE-2024-34245 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php. | |||||
| CVE-2024-34244 | 1 Libmodbus | 1 Libmodbus | 2026-06-17 | N/A | 7.5 HIGH |
| libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors. | |||||
| CVE-2024-34243 | 1 Pantsel | 1 Konga | 2026-06-17 | N/A | 5.4 MEDIUM |
| Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter. | |||||
| CVE-2024-34241 | 1 Rocketsoft | 1 Rocket Lms | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications. | |||||
| CVE-2024-34240 | 1 Qdocs | 1 Smart School | 2026-06-17 | N/A | 6.1 MEDIUM |
| QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records. | |||||
| CVE-2024-34235 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 8.6 HIGH |
| Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service. | |||||
