Vulnerabilities (CVE)

Total 396876 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33161 1 J2eefast 1 J2eefast 2026-06-17 N/A 5.3 MEDIUM
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.
CVE-2024-33155 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.8 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.
CVE-2024-33153 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.8 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.
CVE-2024-33149 1 J2eefast 1 J2eefast 2026-06-17 N/A 8.1 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.
CVE-2024-33148 1 J2eefast 1 J2eefast 2026-06-17 N/A 7.3 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.
CVE-2024-33147 1 J2eefast 1 J2eefast 2026-06-17 N/A 8.8 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.
CVE-2024-33146 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.1 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
CVE-2024-33144 1 J2eefast 1 J2eefast 2026-06-17 N/A 8.8 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.
CVE-2024-33139 1 J2eefast 1 J2eefast 2026-06-17 N/A 7.5 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
CVE-2024-33124 1 Roothub 1 Roothub 2026-06-17 N/A 9.8 CRITICAL
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
CVE-2024-33122 1 Roothub 1 Roothub 2026-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
CVE-2024-33121 1 Roothub 1 Roothub 2026-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
CVE-2024-33118 1 Luckyframe 1 Luckyframeweb 2026-06-17 N/A 7.5 HIGH
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.
CVE-2024-33117 1 Crmeb 1 Crmeb Java 2026-06-17 N/A 5.3 MEDIUM
crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.
CVE-2024-33113 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 5.3 MEDIUM
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
CVE-2024-33112 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
CVE-2024-33111 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 5.4 MEDIUM
D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.
CVE-2024-33110 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 9.1 CRITICAL
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
CVE-2024-33103 2026-06-17 N/A 6.1 MEDIUM
An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product.
CVE-2024-33102 1 Thinksaas 1 Thinksaas 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.