Total
398152 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29384 | 1 Mikegualtieri | 1 Css Exfil Protection | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions. | |||||
| CVE-2024-29376 | 1 Sylius | 1 Sylius | 2026-06-17 | N/A | 6.4 MEDIUM |
| Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book. | |||||
| CVE-2024-29375 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters. | |||||
| CVE-2024-29374 | 1 Moodle | 1 Moodle | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. | |||||
| CVE-2024-29371 | 1 Jose4j Project | 1 Jose4j | 2026-06-17 | N/A | 7.5 HIGH |
| In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression. | |||||
| CVE-2024-29370 | 1 Python-jose Project | 1 Python-jose | 2026-06-17 | N/A | 5.3 MEDIUM |
| In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression. | |||||
| CVE-2024-29368 | 1 Mozilo | 1 Mozilocms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content. | |||||
| CVE-2024-29366 | 1 Dlink | 2 Dir-845l, Dir-845l Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03. | |||||
| CVE-2024-29338 | 1 Anchorcms | 1 Anchor Cms | 2026-06-17 | N/A | 2.4 LOW |
| Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2. | |||||
| CVE-2024-29320 | 1 Wallosapp | 1 Wallos | 2026-06-17 | N/A | 8.1 HIGH |
| Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. | |||||
| CVE-2024-29319 | 1 Personal-management-system | 1 Personal Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls. | |||||
| CVE-2024-29318 | 1 Personal-management-system | 1 Personal Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code. | |||||
| CVE-2024-29316 | 1 Nodebb | 1 Nodebb | 2026-06-17 | N/A | 6.3 MEDIUM |
| NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true. | |||||
| CVE-2024-29309 | 2026-06-17 | N/A | 7.7 HIGH | ||
| An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service. | |||||
| CVE-2024-29303 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection | |||||
| CVE-2024-29302 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 7.5 HIGH |
| SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php. | |||||
| CVE-2024-29301 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 7.5 HIGH |
| SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id= | |||||
| CVE-2024-29292 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters. | |||||
| CVE-2024-29291 | 2026-06-17 | N/A | N/A | ||
| An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged. | |||||
| CVE-2024-29278 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in "create a message ." | |||||
