Total
398152 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29435 | 1 Alldata | 1 Alldata | 2026-06-17 | N/A | 4.1 MEDIUM |
| An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter. | |||||
| CVE-2024-29434 | 1 Alldata | 1 Alldata | 2026-06-17 | N/A | 8.3 HIGH |
| An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file. | |||||
| CVE-2024-29433 | 1 Alldata | 1 Alldata | 2026-06-17 | N/A | 9.8 CRITICAL |
| A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data. | |||||
| CVE-2024-29432 | 1 Alldata | 1 Alldata | 2026-06-17 | N/A | 9.8 CRITICAL |
| Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas. | |||||
| CVE-2024-29421 | 2026-06-17 | N/A | 6.2 MEDIUM | ||
| xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code. | |||||
| CVE-2024-29419 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013. | |||||
| CVE-2024-29417 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function. | |||||
| CVE-2024-29415 | 2026-06-17 | N/A | 8.1 HIGH | ||
| The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282. | |||||
| CVE-2024-29413 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant messenger field in the Contact info function. | |||||
| CVE-2024-29409 | 1 Nestjs | 1 Nest | 2026-06-17 | N/A | 5.5 MEDIUM |
| File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header. | |||||
| CVE-2024-29404 | 2026-06-17 | N/A | 7.8 HIGH | ||
| An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component. | |||||
| CVE-2024-29402 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity. | |||||
| CVE-2024-29401 | 1 Mindskip | 1 Xzs-mysql | 2026-06-17 | N/A | 9.8 CRITICAL |
| xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything. | |||||
| CVE-2024-29400 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter. | |||||
| CVE-2024-29399 | 1 Gnu | 1 Savane | 2026-06-17 | N/A | 7.6 HIGH |
| An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component. | |||||
| CVE-2024-29392 | 1 Silverpeas | 1 Silverpeas | 2026-06-17 | N/A | 5.4 MEDIUM |
| Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController. | |||||
| CVE-2024-29390 | 1 Anujk305 | 1 Daily Expenses Management System | 2026-06-17 | N/A | 7.3 HIGH |
| Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit the 'item' parameter in a POST request to execute arbitrary SQL commands in the backend database. This can be done by injecting specially crafted SQL queries that make the database perform time-consuming operations, thereby confirming the presence of the SQL injection vulnerability based on the delay in the server's response. | |||||
| CVE-2024-29387 | 1 Projeqtor | 1 Projeqtor | 2026-06-17 | N/A | 8.8 HIGH |
| projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php. | |||||
| CVE-2024-29386 | 1 Projeqtor | 1 Projeqtor | 2026-06-17 | N/A | 5.4 MEDIUM |
| projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php. | |||||
| CVE-2024-29385 | 1 Dlink | 2 Dir-845l, Dir-845l Firmware | 2026-06-17 | N/A | 9.0 CRITICAL |
| DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function. | |||||
