Total
396856 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-33682 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23. | |||||
| CVE-2024-33681 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3. | |||||
| CVE-2024-33680 | 1 Mainwp | 1 Mainwp Child Reports | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1. | |||||
| CVE-2024-33679 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5. | |||||
| CVE-2024-33678 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in eranfl ClickCease Click Fraud Protection clickcease-click-fraud-protection.This issue affects ClickCease Click Fraud Protection: from n/a through <= 3.2.7. | |||||
| CVE-2024-33677 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through 0.5.70. | |||||
| CVE-2024-33673 | 1 Veritas | 1 Backup Exec | 2026-06-17 | N/A | 7.8 HIGH |
| An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path. | |||||
| CVE-2024-33672 | 1 Veritas | 1 Netbackup | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files. | |||||
| CVE-2024-33671 | 1 Veritas | 1 Backup Exec | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files. | |||||
| CVE-2024-33670 | 1 Passbolt | 1 Passbolt Api | 2026-06-17 | N/A | 4.3 MEDIUM |
| Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page. | |||||
| CVE-2024-33669 | 1 Passbolt | 1 Passbolt Browser Extension | 2026-06-17 | N/A | 6.1 MEDIUM |
| An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user. | |||||
| CVE-2024-33667 | 1 Zammad | 1 Zammad | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist. | |||||
| CVE-2024-33666 | 1 Zammad | 1 Zammad | 2026-06-17 | N/A | 8.6 HIGH |
| An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents. | |||||
| CVE-2024-33665 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks. | |||||
| CVE-2024-33664 | 1 Python-jose Project | 1 Python-jose | 2026-06-17 | N/A | 5.3 MEDIUM |
| python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319. | |||||
| CVE-2024-33663 | 1 Python-jose Project | 1 Python-jose | 2026-06-17 | N/A | 6.5 MEDIUM |
| python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. | |||||
| CVE-2024-33662 | 1 Portainer | 1 Portainer | 2026-06-17 | N/A | 7.5 HIGH |
| Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. | |||||
| CVE-2024-33661 | 1 Portainer | 1 Portainer | 2026-06-17 | N/A | 9.1 CRITICAL |
| Portainer before 2.20.0 allows redirects when the target is not index.yaml. | |||||
| CVE-2024-33660 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 4.3 MEDIUM |
| An exploit is possible where an actor with physical access can manipulate SPI flash without being detected. | |||||
| CVE-2024-33659 | 1 Ami | 1 Aptio V | 2026-06-17 | N/A | 8.8 HIGH |
| AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability. | |||||
