Vulnerabilities (CVE)

Total 398152 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-29511 1 Artifex 1 Ghostscript 2026-06-17 N/A 7.5 HIGH
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.
CVE-2024-29510 1 Artifex 1 Ghostscript 2026-06-17 N/A 6.3 MEDIUM
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
CVE-2024-29509 1 Artifex 1 Ghostscript 2026-06-17 N/A 8.8 HIGH
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
CVE-2024-29508 1 Artifex 1 Ghostscript 2026-06-17 N/A 3.3 LOW
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
CVE-2024-29507 1 Artifex 1 Ghostscript 2026-06-17 N/A 5.4 MEDIUM
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
CVE-2024-29506 1 Artifex 1 Ghostscript 2026-06-17 N/A 8.8 HIGH
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
CVE-2024-29504 1 Summernote 1 Summernote 2026-06-17 N/A 7.6 HIGH
Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.
CVE-2024-29502 1 Inteset 1 Secure Lockdown 2026-06-17 N/A 6.5 MEDIUM
An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths.
CVE-2024-29500 1 Inteset 1 Secure Lockdown 2026-06-17 N/A 9.8 CRITICAL
An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.
CVE-2024-29499 1 Anchorcms 1 Anchor Cms 2026-06-17 N/A 7.4 HIGH
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.
CVE-2024-29489 1 Jerryscript 1 Jerryscript 2026-06-17 N/A 5.5 MEDIUM
Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.
CVE-2024-29474 1 Zhyd 1 Oneblog 2026-06-17 N/A 5.4 MEDIUM
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.
CVE-2024-29473 1 Zhyd 1 Oneblog 2026-06-17 N/A 6.1 MEDIUM
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.
CVE-2024-29472 1 Zhyd 1 Oneblog 2026-06-17 N/A 5.4 MEDIUM
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.
CVE-2024-29471 1 Zhyd 1 Oneblog 2026-06-17 N/A 5.4 MEDIUM
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.
CVE-2024-29470 1 Zhyd 1 Oneblog 2026-06-17 N/A 6.1 MEDIUM
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.
CVE-2024-29469 1 Zhyd 1 Oneblog 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List parameter under the Lab module.
CVE-2024-29466 2026-06-17 N/A 8.8 HIGH
Directory Traversal vulnerability in lsgwr spring boot online exam v.0.9 allows an attacker to execute arbitrary code via the FileTransUtil.java component.
CVE-2024-29461 1 Projectfloodlight 1 Open Sdn Controller 2026-06-17 N/A 6.3 MEDIUM
An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.
CVE-2024-29460 1 Dronecode 1 Px4 Drone Autopilot 2026-06-17 N/A 6.6 MEDIUM
An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.