Total
398094 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29876 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29875 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29874 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29873 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29872 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29871 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29870 | 1 Sapplica | 1 Sentrifugo | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. | |||||
| CVE-2024-29869 | 1 Apache | 1 Hive | 2026-06-17 | N/A | 5.5 MEDIUM |
| Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue. | |||||
| CVE-2024-29868 | 1 Apache | 1 Streampipes | 2026-06-17 | N/A | 9.1 CRITICAL |
| Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue. | |||||
| CVE-2024-29866 | 1 Datalust | 1 Seq | 2026-06-17 | N/A | 9.1 CRITICAL |
| Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges. | |||||
| CVE-2024-29865 | 1 Logpoint | 1 Siem | 2026-06-17 | N/A | 5.4 MEDIUM |
| Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. | |||||
| CVE-2024-29864 | 1 89luca89 | 1 Distrobox | 2026-06-17 | N/A | 9.8 CRITICAL |
| Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables. | |||||
| CVE-2024-29863 | 2026-06-17 | N/A | 7.8 HIGH | ||
| A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator. | |||||
| CVE-2024-29862 | 1 Chirpstack | 2 Gateway Bridge, Mqtt Forwarder | 2026-06-17 | N/A | 7.5 HIGH |
| The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state. | |||||
| CVE-2024-29857 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. | |||||
| CVE-2024-29855 | 1 Veeam | 1 Recovery Orchestrator | 2026-06-17 | N/A | 9.0 CRITICAL |
| Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator | |||||
| CVE-2024-29853 | 1 Veeam | 1 Veeam Agent For Windows | 2026-06-17 | N/A | 7.8 HIGH |
| An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. | |||||
| CVE-2024-29852 | 1 Veeam | 1 Veeam Backup \& Replication | 2026-06-17 | N/A | 2.7 LOW |
| Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs. | |||||
| CVE-2024-29851 | 1 Veeam | 1 Veeam Backup \& Replication | 2026-06-17 | N/A | 7.2 HIGH |
| Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. | |||||
| CVE-2024-29850 | 1 Veeam | 1 Veeam Backup \& Replication | 2026-06-17 | N/A | 8.8 HIGH |
| Veeam Backup Enterprise Manager allows account takeover via NTLM relay. | |||||
