Vulnerabilities (CVE)

Total 398152 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-29435 1 Alldata 1 Alldata 2026-06-17 N/A 4.1 MEDIUM
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.
CVE-2024-29434 1 Alldata 1 Alldata 2026-06-17 N/A 8.3 HIGH
An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.
CVE-2024-29433 1 Alldata 1 Alldata 2026-06-17 N/A 9.8 CRITICAL
A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.
CVE-2024-29432 1 Alldata 1 Alldata 2026-06-17 N/A 9.8 CRITICAL
Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.
CVE-2024-29421 2026-06-17 N/A 6.2 MEDIUM
xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.
CVE-2024-29419 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 5.4 MEDIUM
There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.
CVE-2024-29417 2026-06-17 N/A 8.4 HIGH
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.
CVE-2024-29415 2026-06-17 N/A 8.1 HIGH
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
CVE-2024-29413 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant messenger field in the Contact info function.
CVE-2024-29409 1 Nestjs 1 Nest 2026-06-17 N/A 5.5 MEDIUM
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
CVE-2024-29404 2026-06-17 N/A 7.8 HIGH
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.
CVE-2024-29402 2026-06-17 N/A 4.3 MEDIUM
cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity.
CVE-2024-29401 1 Mindskip 1 Xzs-mysql 2026-06-17 N/A 9.8 CRITICAL
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
CVE-2024-29400 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 7.5 HIGH
An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.
CVE-2024-29399 1 Gnu 1 Savane 2026-06-17 N/A 7.6 HIGH
An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
CVE-2024-29392 1 Silverpeas 1 Silverpeas 2026-06-17 N/A 5.4 MEDIUM
Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.
CVE-2024-29390 1 Anujk305 1 Daily Expenses Management System 2026-06-17 N/A 7.3 HIGH
Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit the 'item' parameter in a POST request to execute arbitrary SQL commands in the backend database. This can be done by injecting specially crafted SQL queries that make the database perform time-consuming operations, thereby confirming the presence of the SQL injection vulnerability based on the delay in the server's response.
CVE-2024-29387 1 Projeqtor 1 Projeqtor 2026-06-17 N/A 8.8 HIGH
projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.
CVE-2024-29386 1 Projeqtor 1 Projeqtor 2026-06-17 N/A 5.4 MEDIUM
projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.
CVE-2024-29385 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 9.0 CRITICAL
DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.