Total
398387 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27733 | 2026-06-17 | N/A | 7.7 HIGH | ||
| File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component. | |||||
| CVE-2024-27731 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parameter. | |||||
| CVE-2024-27730 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 9.8 CRITICAL |
| Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature. | |||||
| CVE-2024-27729 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature. | |||||
| CVE-2024-27728 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature. | |||||
| CVE-2024-27719 | 1 Rems | 1 Faq Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function. | |||||
| CVE-2024-27718 | 2026-06-17 | N/A | 7.8 HIGH | ||
| SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component. | |||||
| CVE-2024-27717 | 1 Eskooly | 1 Eskooly | 2026-06-17 | N/A | 6.5 MEDIUM |
| Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling component. | |||||
| CVE-2024-27716 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user input fields. | |||||
| CVE-2024-27715 | 1 Eskooly | 1 Eskooly | 2026-06-17 | N/A | 8.2 HIGH |
| An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism. | |||||
| CVE-2024-27713 | 1 Eskooly | 1 Eskooly | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component. | |||||
| CVE-2024-27712 | 1 Eskooly | 1 Eskooly | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component in the authentication mechanism. | |||||
| CVE-2024-27711 | 1 Eskooly | 1 Eskooly | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings. | |||||
| CVE-2024-27710 | 1 Eskooly | 1 Eskooly | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism. | |||||
| CVE-2024-27709 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component. | |||||
| CVE-2024-27708 | 1 Airc | 1 Mynet | 2026-06-17 | N/A | 9.6 CRITICAL |
| Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter. | |||||
| CVE-2024-27707 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file. | |||||
| CVE-2024-27706 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues. | |||||
| CVE-2024-27705 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 7.6 HIGH |
| Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint. | |||||
| CVE-2024-27703 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter. | |||||
