Total
398119 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29732 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter. | |||||
| CVE-2024-29731 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/ , parameters idChallenge and idEmpresa. | |||||
| CVE-2024-29730 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ , parameter idCat;. | |||||
| CVE-2024-29729 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/, parameter url. | |||||
| CVE-2024-29728 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ , parameter idDesafio. | |||||
| CVE-2024-29727 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRemember/ , parameter send. | |||||
| CVE-2024-29726 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/, parameter id. | |||||
| CVE-2024-29725 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/, parameter list. | |||||
| CVE-2024-29724 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter idDesafio. | |||||
| CVE-2024-29723 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/, parameter categoria;. | |||||
| CVE-2024-29720 | 1 Terrainformatica | 1 Sciter | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function. | |||||
| CVE-2024-29686 | 1 Wintercms | 1 Winter | 2026-06-17 | N/A | 7.2 HIGH |
| Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them. | |||||
| CVE-2024-29684 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code. | |||||
| CVE-2024-29672 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt. | |||||
| CVE-2024-29671 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component. | |||||
| CVE-2024-29667 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter. | |||||
| CVE-2024-29666 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component. | |||||
| CVE-2024-29661 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload. | |||||
| CVE-2024-29660 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.3 MEDIUM |
| Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payload to the stepselect_main.php component. | |||||
| CVE-2024-29651 | 2026-06-17 | N/A | 8.1 HIGH | ||
| A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions. | |||||
