Total
396876 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-33327 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter. | |||||
| CVE-2024-33326 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter. | |||||
| CVE-2024-33309 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information via an insecure API endpoint. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |||||
| CVE-2024-33308 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact Feature. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |||||
| CVE-2024-33307 | 1 Sourcecodester | 1 Laboratory Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User. | |||||
| CVE-2024-33306 | 1 Sourcecodester | 1 Laboratory Management System | 2026-06-17 | N/A | 7.4 HIGH |
| SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User. | |||||
| CVE-2024-33305 | 1 Sourcecodester | 1 Laboratory Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User. | |||||
| CVE-2024-33304 | 1 Oretnom23 | 1 Product Show Room Site | 2026-06-17 | N/A | 6.1 MEDIUM |
| SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users. | |||||
| CVE-2024-33303 | 1 Oretnom23 | 1 Product Show Room Site | 2026-06-17 | N/A | 8.2 HIGH |
| SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users. | |||||
| CVE-2024-33302 | 1 Oretnom23 | 1 Product Show Room Site | 2026-06-17 | N/A | 5.3 MEDIUM |
| SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users. | |||||
| CVE-2024-33300 | 1 Typora | 1 Typora | 2026-06-17 | N/A | 7.3 HIGH |
| Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files. | |||||
| CVE-2024-33299 | 1 Microweber | 1 Microweber | 2026-06-17 | N/A | 4.7 MEDIUM |
| Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users | |||||
| CVE-2024-33298 | 1 Microweber | 1 Microweber | 2026-06-17 | N/A | 6.1 MEDIUM |
| Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup | |||||
| CVE-2024-33297 | 1 Microweber | 1 Microweber | 2026-06-17 | N/A | 4.7 MEDIUM |
| Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function | |||||
| CVE-2024-33294 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the student_edit_photo.php component. | |||||
| CVE-2024-33292 | 2026-06-17 | N/A | 8.2 HIGH | ||
| SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the id parameter. | |||||
| CVE-2024-33288 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page. | |||||
| CVE-2024-33278 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker to execute arbitrary code via the connection_state_machine due to improper length validation for the cookie field. | |||||
| CVE-2024-33276 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method. | |||||
| CVE-2024-33275 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components. | |||||
