Vulnerabilities (CVE)

Total 398387 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-27630 1 Gnu 1 Savane 2026-06-17 N/A 7.5 HIGH
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
CVE-2024-27629 2026-06-17 N/A 7.8 HIGH
An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.
CVE-2024-27628 1 Offis 1 Dcmtk 2026-06-17 N/A 8.1 HIGH
Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.
CVE-2024-27627 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page.
CVE-2024-27626 1 Dotclear 1 Dotclear 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.
CVE-2024-27625 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 4.8 MEDIUM
CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field.
CVE-2024-27623 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 5.9 MEDIUM
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.
CVE-2024-27622 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 7.2 HIGH
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
CVE-2024-27613 1 Numbas 1 Editor 2026-06-17 N/A 7.3 HIGH
Numbas editor before 7.3 mishandles reading of themes and extensions.
CVE-2024-27612 1 Numbas 1 Editor 2026-06-17 N/A 6.2 MEDIUM
Numbas editor before 7.3 mishandles editing of themes and extensions.
CVE-2024-27609 2026-06-17 N/A 6.5 MEDIUM
Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel.
CVE-2024-27605 1 Alldata 1 Alldata 2026-06-17 N/A 7.5 HIGH
Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.
CVE-2024-27604 1 Alldata 1 Alldata 2026-06-17 N/A 9.8 CRITICAL
Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.
CVE-2024-27602 1 Alldata 1 Alldata 2026-06-17 N/A 9.1 CRITICAL
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.
CVE-2024-27593 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.
CVE-2024-27592 1 Corezoid 1 Corezoid 2026-06-17 N/A 4.3 MEDIUM
Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.
CVE-2024-27575 2026-06-17 N/A 7.5 HIGH
INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as with the /cgi-bin/display?file=/etc/passwd URI.
CVE-2024-27574 2026-06-17 N/A 9.1 CRITICAL
SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters.
CVE-2024-27572 1 Libtor 2 Lbt-t300-t390, Lbt-t300-t390 Firmware 2026-06-17 N/A 7.5 HIGH
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-27571 1 Libtor 2 Lbt-t300-t390, Lbt-t300-t390 Firmware 2026-06-17 N/A 7.5 HIGH
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the makeCurRemoteApList function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.