Total
398387 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27773 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 8.8 HIGH |
| Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE | |||||
| CVE-2024-27772 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 8.8 HIGH |
| Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE | |||||
| CVE-2024-27771 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 8.8 HIGH |
| Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE | |||||
| CVE-2024-27770 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 8.8 HIGH |
| Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal | |||||
| CVE-2024-27769 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 8.8 HIGH |
| Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices | |||||
| CVE-2024-27768 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 9.8 CRITICAL |
| Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE | |||||
| CVE-2024-27767 | 1 Unitronics | 1 Unilogic | 2026-06-17 | N/A | 10.0 CRITICAL |
| CWE-287: Improper Authentication may allow Authentication Bypass | |||||
| CVE-2024-27766 | 1 Mariadb | 1 Mariadb | 2026-06-17 | N/A | 5.7 MEDIUM |
| An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |||||
| CVE-2024-27765 | 1 Jeewms | 1 Jeewms | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component. | |||||
| CVE-2024-27764 | 1 Jeewms | 1 Jeewms | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component. | |||||
| CVE-2024-27763 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable. | |||||
| CVE-2024-27758 | 2026-06-17 | N/A | 8.4 HIGH | ||
| In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution. | |||||
| CVE-2024-27757 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 6.1 MEDIUM |
| flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS. The reporter indicates that this product "ceased its development as of February 2024." | |||||
| CVE-2024-27756 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 8.8 HIGH |
| GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title. | |||||
| CVE-2024-27752 | 1 Cszcms | 1 Csz Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function. | |||||
| CVE-2024-27747 | 1 Mayurik | 1 Petrol Pump Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component. | |||||
| CVE-2024-27746 | 1 Mayurik | 1 Petrol Pump Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | |||||
| CVE-2024-27744 | 1 Mayurik | 1 Petrol Pump Management | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component. | |||||
| CVE-2024-27743 | 1 Mayurik | 1 Petrol Pump Management | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component. | |||||
| CVE-2024-27734 | 1 Cszcms | 1 Csz Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fields of the Site Settings component. | |||||
