Vulnerabilities (CVE)

Total 398149 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-29720 1 Terrainformatica 1 Sciter 2026-06-17 N/A 5.5 MEDIUM
An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function.
CVE-2024-29686 1 Wintercms 1 Winter 2026-06-17 N/A 7.2 HIGH
Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server that hosts Winter CMS, or a developer working for them.
CVE-2024-29684 1 Dedecms 1 Dedecms 2026-06-17 N/A 9.8 CRITICAL
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attacker to execute arbitrary code.
CVE-2024-29672 2026-06-17 N/A 8.8 HIGH
Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.
CVE-2024-29671 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.
CVE-2024-29667 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.
CVE-2024-29666 2026-06-17 N/A 9.8 CRITICAL
Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component.
CVE-2024-29661 1 Dedecms 1 Dedecms 2026-06-17 N/A 9.8 CRITICAL
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
CVE-2024-29660 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.3 MEDIUM
Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payload to the stepselect_main.php component.
CVE-2024-29651 2026-06-17 N/A 8.1 HIGH
A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.
CVE-2024-29650 2026-06-17 N/A 9.8 CRITICAL
An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.
CVE-2024-29646 1 Radare 1 Radare2 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.
CVE-2024-29645 1 Radare 1 Radare2 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.
CVE-2024-29643 1 Croogo 1 Croogo 2026-06-17 N/A 9.1 CRITICAL
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
CVE-2024-29515 1 Lepton-cms 1 Leptoncms 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.
CVE-2024-29514 1 Lepton-cms 1 Leptoncms 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2024-29513 2026-06-17 N/A 7.8 HIGH
An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.
CVE-2024-29511 1 Artifex 1 Ghostscript 2026-06-17 N/A 7.5 HIGH
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
CVE-2024-29510 1 Artifex 1 Ghostscript 2026-06-17 N/A 6.3 MEDIUM
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
CVE-2024-29509 1 Artifex 1 Ghostscript 2026-06-17 N/A 8.8 HIGH
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.