Total
396856 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-33831 | 2026-06-17 | N/A | 7.4 HIGH | ||
| A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field. | |||||
| CVE-2024-33830 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.1 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache. | |||||
| CVE-2024-33829 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 5.4 MEDIUM |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache. | |||||
| CVE-2024-33820 | 1 Totolink | 2 A3002r, A3002r Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow. | |||||
| CVE-2024-33819 | 2026-06-17 | N/A | 4.6 MEDIUM | ||
| Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function. | |||||
| CVE-2024-33818 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter. | |||||
| CVE-2024-33809 | 1 Pingcap | 1 Tidb | 2026-06-17 | N/A | 6.5 MEDIUM |
| PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks. | |||||
| CVE-2024-33808 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33807 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter. | |||||
| CVE-2024-33806 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33805 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33804 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 6.3 MEDIUM |
| A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33803 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33802 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter. | |||||
| CVE-2024-33801 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33800 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter. | |||||
| CVE-2024-33799 | 1 Campcodes | 1 Complete Web-based School Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | |||||
| CVE-2024-33793 | 1 Netis-systems | 2 Mex605, Mex605 Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page. | |||||
| CVE-2024-33792 | 1 Netis-systems | 2 Mex605, Mex605 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page. | |||||
| CVE-2024-33791 | 1 Netis-systems | 2 Mex605, Mex605 Firmware | 2026-06-17 | N/A | 4.6 MEDIUM |
| A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function. | |||||
