Vulnerabilities (CVE)

Total 396633 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-34313 2026-06-17 N/A 9.8 CRITICAL
An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.
CVE-2024-34312 1 Moodle 1 Virtual Programming Lab 2026-06-17 N/A 6.1 MEDIUM
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
CVE-2024-34310 2026-06-17 N/A 8.8 HIGH
Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2024-34308 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.
CVE-2024-34274 2026-06-17 N/A 3.9 LOW
OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-34273 2026-06-17 N/A 5.9 MEDIUM
njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.
CVE-2024-34257 1 Totolink 2 Ex1800t, Ex1800t Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
CVE-2024-34256 1 Ofcms Project 1 Ofcms 2026-06-17 N/A 9.8 CRITICAL
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
CVE-2024-34255 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 6.1 MEDIUM
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.
CVE-2024-34252 1 Wasm3 Project 1 Wasm3 2026-06-17 N/A 7.5 HIGH
wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.
CVE-2024-34251 1 Bytecodealliance 1 Webassembly Micro Runtime 2026-06-17 N/A 7.5 HIGH
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
CVE-2024-34250 1 Bytecodealliance 1 Webassembly Micro Runtime 2026-06-17 N/A 6.2 MEDIUM
A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.
CVE-2024-34249 1 Wasm3 Project 1 Wasm3 2026-06-17 N/A 9.8 CRITICAL
wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.
CVE-2024-34246 1 Wasm3 Project 1 Wasm3 2026-06-17 N/A 7.5 HIGH
wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.
CVE-2024-34245 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.
CVE-2024-34244 1 Libmodbus 1 Libmodbus 2026-06-17 N/A 7.5 HIGH
libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors.
CVE-2024-34243 1 Pantsel 1 Konga 2026-06-17 N/A 5.4 MEDIUM
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
CVE-2024-34241 1 Rocketsoft 1 Rocket Lms 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.
CVE-2024-34240 1 Qdocs 1 Smart School 2026-06-17 N/A 6.1 MEDIUM
QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records.
CVE-2024-34235 1 Open5gs 1 Open5gs 2026-06-17 N/A 8.6 HIGH
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.