Vulnerabilities (CVE)

Total 396909 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-31682 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.
CVE-2024-31680 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
CVE-2024-31678 1 Razormist 1 Loan Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.
CVE-2024-31673 1 Kliqqi 1 Kliqqi Cms 2026-06-17 N/A 9.8 CRITICAL
Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.
CVE-2024-31670 1 Rizin 1 Rizin 2026-06-17 N/A 6.3 MEDIUM
rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.
CVE-2024-31669 1 Rizin 1 Rizin 2026-06-17 N/A 7.5 HIGH
rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide.
CVE-2024-31668 1 Rizin 1 Rizin 2026-06-17 N/A 9.1 CRITICAL
rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.
CVE-2024-31666 1 Flusity 1 Flusity 2026-06-17 N/A 9.8 CRITICAL
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.
CVE-2024-31652 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.
CVE-2024-31651 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.
CVE-2024-31650 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2026-06-17 N/A 9.6 CRITICAL
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.
CVE-2024-31649 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
CVE-2024-31648 1 Munyweki 1 Insurance Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.
CVE-2024-31634 1 Xunruicms 1 Xunruicms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog \XunRuiCMS\dayrui\Fcms\Library.
CVE-2024-31621 1 Flowiseai 1 Flowise 2026-06-17 N/A 7.6 HIGH
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
CVE-2024-31617 1 Litespeedtech 1 Openlitespeed 2026-06-17 N/A 5.3 MEDIUM
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
CVE-2024-31616 2026-06-17 N/A 8.8 HIGH
An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910) allows attackers to execute arbitrary code via the common_quick_config.lua file.
CVE-2024-31615 1 Thinkcmf 1 Thinkcmf 2026-06-17 N/A 9.8 CRITICAL
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2024-31613 1 Bosscms 1 Bosscms 2026-06-17 N/A 5.4 MEDIUM
BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
CVE-2024-31612 1 Emlog 1 Emlog 2026-06-17 N/A 6.5 MEDIUM
Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.