Vulnerabilities (CVE)

Total 396856 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33831 2026-06-17 N/A 7.4 HIGH
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field.
CVE-2024-33830 1 Idccms 1 Idccms 2026-06-17 N/A 8.1 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.
CVE-2024-33829 1 Idccms 1 Idccms 2026-06-17 N/A 5.4 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.
CVE-2024-33820 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 7.5 HIGH
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
CVE-2024-33819 2026-06-17 N/A 4.6 MEDIUM
Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.
CVE-2024-33818 2026-06-17 N/A 7.5 HIGH
Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.
CVE-2024-33809 1 Pingcap 1 Tidb 2026-06-17 N/A 6.5 MEDIUM
PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.
CVE-2024-33808 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33807 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.
CVE-2024-33806 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33805 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33804 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 6.3 MEDIUM
A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33803 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33802 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 6.5 MEDIUM
A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.
CVE-2024-33801 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33800 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.
CVE-2024-33799 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33793 1 Netis-systems 2 Mex605, Mex605 Firmware 2026-06-17 N/A 5.3 MEDIUM
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.
CVE-2024-33792 1 Netis-systems 2 Mex605, Mex605 Firmware 2026-06-17 N/A 9.8 CRITICAL
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.
CVE-2024-33791 1 Netis-systems 2 Mex605, Mex605 Firmware 2026-06-17 N/A 4.6 MEDIUM
A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.