Total
398160 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29237 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29236 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29235 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29234 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29233 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29232 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29231 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29230 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29229 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 7.7 HIGH |
| Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2024-29228 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 7.7 HIGH |
| Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2024-29227 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29225 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request. | |||||
| CVE-2024-29224 | 1 Mayuresh82 | 1 Gocast | 2026-06-17 | N/A | 9.8 CRITICAL |
| An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |||||
| CVE-2024-29223 | 1 Intel | 1 Quickassist Technology | 2026-06-17 | N/A | 6.7 MEDIUM |
| Uncontrolled search path for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |||||
| CVE-2024-29222 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable denial of service via local access. | |||||
| CVE-2024-29221 | 1 Mattermost | 1 Mattermost Server | 2026-06-17 | N/A | 4.7 MEDIUM |
| Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins. | |||||
| CVE-2024-29220 | 1 Ninjaforms | 1 Ninja Forms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product. | |||||
| CVE-2024-29219 | 1 Keyence | 6 Kv Replay Viewer, Kv Studio, Vt5-wx12 and 3 more | 2026-06-17 | N/A | 7.8 HIGH |
| Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. | |||||
| CVE-2024-29218 | 1 Keyence | 6 Kv Replay Viewer, Kv Studio, Vt5-wx12 and 3 more | 2026-06-17 | N/A | 8.8 HIGH |
| Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. | |||||
| CVE-2024-29217 | 1 Apache | 1 Answer | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack. Users are recommended to upgrade to version [1.3.0], which fixes the issue. | |||||
