Vulnerabilities (CVE)

Total 398081 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-29876 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29875 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29874 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29873 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29872 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29871 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29870 1 Sapplica 1 Sentrifugo 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
CVE-2024-29869 1 Apache 1 Hive 2026-06-17 N/A 5.5 MEDIUM
Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue.
CVE-2024-29868 1 Apache 1 Streampipes 2026-06-17 N/A 9.1 CRITICAL
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.
CVE-2024-29866 1 Datalust 1 Seq 2026-06-17 N/A 9.1 CRITICAL
Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.
CVE-2024-29865 1 Logpoint 1 Siem 2026-06-17 N/A 5.4 MEDIUM
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2024-29864 1 89luca89 1 Distrobox 2026-06-17 N/A 9.8 CRITICAL
Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.
CVE-2024-29863 2026-06-17 N/A 7.8 HIGH
A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.
CVE-2024-29862 1 Chirpstack 2 Gateway Bridge, Mqtt Forwarder 2026-06-17 N/A 7.5 HIGH
The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.
CVE-2024-29857 2026-06-17 N/A 7.5 HIGH
An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.
CVE-2024-29855 1 Veeam 1 Recovery Orchestrator 2026-06-17 N/A 9.0 CRITICAL
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
CVE-2024-29853 1 Veeam 1 Veeam Agent For Windows 2026-06-17 N/A 7.8 HIGH
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
CVE-2024-29852 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 2.7 LOW
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
CVE-2024-29851 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 7.2 HIGH
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
CVE-2024-29850 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 8.8 HIGH
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.