Total
396876 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-33161 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 5.3 MEDIUM |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function. | |||||
| CVE-2024-33155 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 9.8 CRITICAL |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function. | |||||
| CVE-2024-33153 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 9.8 CRITICAL |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function. | |||||
| CVE-2024-33149 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 8.1 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function. | |||||
| CVE-2024-33148 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 7.3 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function. | |||||
| CVE-2024-33147 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 8.8 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function. | |||||
| CVE-2024-33146 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 9.1 CRITICAL |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function. | |||||
| CVE-2024-33144 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 8.8 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml. | |||||
| CVE-2024-33139 | 1 J2eefast | 1 J2eefast | 2026-06-17 | N/A | 7.5 HIGH |
| J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function. | |||||
| CVE-2024-33124 | 1 Roothub | 1 Roothub | 2026-06-17 | N/A | 9.8 CRITICAL |
| Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function.. | |||||
| CVE-2024-33122 | 1 Roothub | 1 Roothub | 2026-06-17 | N/A | 6.3 MEDIUM |
| Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function. | |||||
| CVE-2024-33121 | 1 Roothub | 1 Roothub | 2026-06-17 | N/A | 6.3 MEDIUM |
| Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. | |||||
| CVE-2024-33118 | 1 Luckyframe | 1 Luckyframeweb | 2026-06-17 | N/A | 7.5 HIGH |
| LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController. | |||||
| CVE-2024-33117 | 1 Crmeb | 1 Crmeb Java | 2026-06-17 | N/A | 5.3 MEDIUM |
| crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. | |||||
| CVE-2024-33113 | 1 Dlink | 2 Dir-845l, Dir-845l Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php. | |||||
| CVE-2024-33112 | 1 Dlink | 2 Dir-845l, Dir-845l Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func. | |||||
| CVE-2024-33111 | 1 Dlink | 2 Dir-845l, Dir-845l Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php. | |||||
| CVE-2024-33110 | 1 Dlink | 2 Dir-845l, Dir-845l Firmware | 2026-06-17 | N/A | 9.1 CRITICAL |
| D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component. | |||||
| CVE-2024-33103 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product. | |||||
| CVE-2024-33102 | 1 Thinksaas | 1 Thinksaas | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter. | |||||
