Total
398385 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-28442 | 1 Yealink | 2 Vp59, Vp59 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component. | |||||
| CVE-2024-28441 | 1 Magicflue | 1 Magicflue | 2026-06-17 | N/A | 9.8 CRITICAL |
| File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint. | |||||
| CVE-2024-28436 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component. | |||||
| CVE-2024-28435 | 1 Twenty | 1 Twenty | 2026-06-17 | N/A | 5.4 MEDIUM |
| The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload. | |||||
| CVE-2024-28434 | 1 Twenty | 1 Twenty | 2026-06-17 | N/A | 7.6 HIGH |
| The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code. | |||||
| CVE-2024-28432 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 8.8 HIGH |
| DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php. | |||||
| CVE-2024-28431 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 8.8 HIGH |
| DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php. | |||||
| CVE-2024-28430 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 6.1 MEDIUM |
| DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php. | |||||
| CVE-2024-28429 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.5 MEDIUM |
| DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php | |||||
| CVE-2024-28425 | 1 Linkedin | 1 Greykite | 2026-06-17 | N/A | 7.5 HIGH |
| greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-28424 | 1 Zenml | 1 Zenml | 2026-06-17 | N/A | 8.8 HIGH |
| zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-28423 | 1 Feluelle | 1 Airflow-diagrams | 2026-06-17 | N/A | 9.8 CRITICAL |
| Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file. | |||||
| CVE-2024-28421 | 1 Cobub | 1 Razor | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php | |||||
| CVE-2024-28418 | 1 Webedition | 1 Webedition Cms | 2026-06-17 | N/A | 6.5 MEDIUM |
| Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php | |||||
| CVE-2024-28417 | 1 Webedition | 1 Webedition Cms | 2026-06-17 | N/A | 6.3 MEDIUM |
| Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php. | |||||
| CVE-2024-28405 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 7.2 HIGH |
| SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges. | |||||
| CVE-2024-28404 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page. | |||||
| CVE-2024-28403 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page. | |||||
| CVE-2024-28402 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 5.9 MEDIUM |
| TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page. | |||||
| CVE-2024-28401 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page. | |||||
