Vulnerabilities (CVE)

Total 396943 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30880 1 Rageframe 1 Rageframe 2026-06-17 N/A 5.4 MEDIUM
Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the multiple parameter in the image cropping function.
CVE-2024-30879 1 Rageframe 1 Rageframe 2026-06-17 N/A 6.1 MEDIUM
Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the boxId parameter in the image cropping function.
CVE-2024-30878 1 Rageframe 1 Rageframe 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the upload_drive parameter.
CVE-2024-30875 2026-06-17 N/A 7.1 HIGH
Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the window.addEventListener component. NOTE: this is disputed by the Supplier because it cannot be reproduced, and because the exploitation example does not indicate whether, or how, the example website is using jQuery UI.
CVE-2024-30872 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 5.1 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.
CVE-2024-30871 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.
CVE-2024-30870 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.
CVE-2024-30868 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.
CVE-2024-30867 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.
CVE-2024-30866 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 5.4 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.
CVE-2024-30865 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.
CVE-2024-30864 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 6.3 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.
CVE-2024-30863 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 6.3 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.
CVE-2024-30862 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.
CVE-2024-30861 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 5.3 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.
CVE-2024-30860 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.
CVE-2024-30859 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.
CVE-2024-30858 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.
CVE-2024-30855 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
CVE-2024-30851 1 Codesiddhant 1 Jasmin-ransomware 2026-06-17 N/A 6.5 MEDIUM
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the download_file.php component.