Vulnerabilities (CVE)

Total 398385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28442 1 Yealink 2 Vp59, Vp59 Firmware 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.
CVE-2024-28441 1 Magicflue 1 Magicflue 2026-06-17 N/A 9.8 CRITICAL
File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint.
CVE-2024-28436 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.
CVE-2024-28435 1 Twenty 1 Twenty 2026-06-17 N/A 5.4 MEDIUM
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
CVE-2024-28434 1 Twenty 1 Twenty 2026-06-17 N/A 7.6 HIGH
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
CVE-2024-28432 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.
CVE-2024-28431 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.
CVE-2024-28430 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.1 MEDIUM
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.
CVE-2024-28429 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.5 MEDIUM
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php
CVE-2024-28425 1 Linkedin 1 Greykite 2026-06-17 N/A 7.5 HIGH
greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-28424 1 Zenml 1 Zenml 2026-06-17 N/A 8.8 HIGH
zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-28423 1 Feluelle 1 Airflow-diagrams 2026-06-17 N/A 9.8 CRITICAL
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.
CVE-2024-28421 1 Cobub 1 Razor 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php
CVE-2024-28418 1 Webedition 1 Webedition Cms 2026-06-17 N/A 6.5 MEDIUM
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CVE-2024-28417 1 Webedition 1 Webedition Cms 2026-06-17 N/A 6.3 MEDIUM
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
CVE-2024-28405 1 Sem-cms 1 Semcms 2026-06-17 N/A 7.2 HIGH
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
CVE-2024-28404 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
CVE-2024-28403 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 5.4 MEDIUM
TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.
CVE-2024-28402 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 5.9 MEDIUM
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
CVE-2024-28401 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 5.4 MEDIUM
TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.