Vulnerabilities (CVE)

Total 398152 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-29384 1 Mikegualtieri 1 Css Exfil Protection 2026-06-17 N/A 7.5 HIGH
An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.
CVE-2024-29376 1 Sylius 1 Sylius 2026-06-17 N/A 6.4 MEDIUM
Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
CVE-2024-29375 2026-06-17 N/A 9.8 CRITICAL
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.
CVE-2024-29374 1 Moodle 1 Moodle 2026-06-17 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
CVE-2024-29371 1 Jose4j Project 1 Jose4j 2026-06-17 N/A 7.5 HIGH
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
CVE-2024-29370 1 Python-jose Project 1 Python-jose 2026-06-17 N/A 5.3 MEDIUM
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
CVE-2024-29368 1 Mozilo 1 Mozilocms 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.
CVE-2024-29366 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 8.8 HIGH
A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
CVE-2024-29338 1 Anchorcms 1 Anchor Cms 2026-06-17 N/A 2.4 LOW
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.
CVE-2024-29320 1 Wallosapp 1 Wallos 2026-06-17 N/A 8.1 HIGH
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
CVE-2024-29319 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 9.8 CRITICAL
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.
CVE-2024-29318 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 5.4 MEDIUM
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.
CVE-2024-29316 1 Nodebb 1 Nodebb 2026-06-17 N/A 6.3 MEDIUM
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
CVE-2024-29309 2026-06-17 N/A 7.7 HIGH
An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.
CVE-2024-29303 1 Mayurik 1 Php Task Management System 2026-06-17 N/A 9.8 CRITICAL
The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
CVE-2024-29302 1 Mayurik 1 Php Task Management System 2026-06-17 N/A 7.5 HIGH
SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.
CVE-2024-29301 1 Mayurik 1 Php Task Management System 2026-06-17 N/A 7.5 HIGH
SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=
CVE-2024-29292 2026-06-17 N/A 9.1 CRITICAL
Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.
CVE-2024-29291 2026-06-17 N/A N/A
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged.
CVE-2024-29278 2026-06-17 N/A 6.5 MEDIUM
funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in "create a message ."