Vulnerabilities (CVE)

Total 396943 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30928 1 Derbynet 1 Derbynet 2026-06-17 N/A 8.1 HIGH
SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc
CVE-2024-30927 1 Derbynet 1 Derbynet 2026-06-17 N/A 6.3 MEDIUM
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.
CVE-2024-30926 1 Derbynet 1 Derbynet 2026-06-17 N/A 4.6 MEDIUM
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.
CVE-2024-30925 1 Derbynet 1 Derbynet 2026-06-17 N/A 6.5 MEDIUM
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.
CVE-2024-30924 1 Derbynet 1 Derbynet 2026-06-17 N/A 4.6 MEDIUM
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
CVE-2024-30923 1 Derbynet 1 Derbynet 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering
CVE-2024-30922 1 Derbynet 1 Derbynet 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering.
CVE-2024-30921 1 Derbynet 1 Derbynet 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.
CVE-2024-30920 1 Derbynet 1 Derbynet 2026-06-17 N/A 7.4 HIGH
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component.
CVE-2024-30917 1 Eprosima 1 Fast Dds 2026-06-17 N/A 5.5 MEDIUM
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.
CVE-2024-30916 1 Eprosima 1 Fast Dds 2026-06-17 N/A 7.1 HIGH
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.
CVE-2024-30915 1 Objectcomputing 1 Opendds 2026-06-17 N/A 4.3 MEDIUM
An issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service and obtain sensitive information via the max_samples parameter within the DataReaderQoS component.
CVE-2024-30896 2026-06-17 N/A 9.1 CRITICAL
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API. The supplier has stated that InfluxDB 2.8.0 has addressed this issue.
CVE-2024-30891 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 8.8 HIGH
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
CVE-2024-30890 1 Ed01-cms Project 1 Ed01-cms 2026-06-17 N/A 4.7 MEDIUM
Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.
CVE-2024-30889 1 Web-audimex 1 Audimexee 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, request_id, payload parameters.
CVE-2024-30886 1 Hadsky 1 Hadsky 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.
CVE-2024-30885 1 Hadsky 1 Hadsky 2026-06-17 N/A 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive information via the chklogin.php component .
CVE-2024-30884 1 Discuz 1 Discuzx 2026-06-17 N/A 7.1 HIGH
Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and obtain sensitive information via crafted payload to the primarybegin parameter in the misc.php component.
CVE-2024-30883 1 Rageframe 1 Rageframe 2026-06-17 N/A 4.7 MEDIUM
Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the aspectRatio parameter in the image cropping function.