Vulnerabilities (CVE)

Total 396665 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-34255 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 6.1 MEDIUM
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.
CVE-2024-34252 1 Wasm3 Project 1 Wasm3 2026-06-17 N/A 7.5 HIGH
wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.
CVE-2024-34251 1 Bytecodealliance 1 Webassembly Micro Runtime 2026-06-17 N/A 7.5 HIGH
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
CVE-2024-34250 1 Bytecodealliance 1 Webassembly Micro Runtime 2026-06-17 N/A 6.2 MEDIUM
A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.
CVE-2024-34249 1 Wasm3 Project 1 Wasm3 2026-06-17 N/A 9.8 CRITICAL
wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.
CVE-2024-34246 1 Wasm3 Project 1 Wasm3 2026-06-17 N/A 7.5 HIGH
wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.
CVE-2024-34245 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.
CVE-2024-34244 1 Libmodbus 1 Libmodbus 2026-06-17 N/A 7.5 HIGH
libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors.
CVE-2024-34243 1 Pantsel 1 Konga 2026-06-17 N/A 5.4 MEDIUM
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
CVE-2024-34241 1 Rocketsoft 1 Rocket Lms 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.
CVE-2024-34240 1 Qdocs 1 Smart School 2026-06-17 N/A 6.1 MEDIUM
QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records.
CVE-2024-34235 1 Open5gs 1 Open5gs 2026-06-17 N/A 8.6 HIGH
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.
CVE-2024-34231 1 Sourcecodester 1 Laboratory Management System 2026-06-17 N/A 7.1 HIGH
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.
CVE-2024-34230 1 Sourcecodester 1 Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.
CVE-2024-34226 1 Oretnom23 1 Visitor Management System 2026-06-17 N/A 9.4 CRITICAL
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
CVE-2024-34225 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
CVE-2024-34224 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVE-2024-34223 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 4.3 MEDIUM
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.
CVE-2024-34222 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 5.9 MEDIUM
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVE-2024-34221 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.