Total
398387 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27516 | 1 Livehelperchat | 1 Live Helper Chat | 2026-06-17 | N/A | 9.8 CRITICAL |
| Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php. | |||||
| CVE-2024-27515 | 1 Mindstellar | 1 Osclass | 2026-06-17 | N/A | 7.2 HIGH |
| Osclass 5.1.2 is vulnerable to SQL Injection. | |||||
| CVE-2024-27508 | 1 Atheme | 1 Atheme | 2026-06-17 | N/A | 7.5 HIGH |
| Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c. | |||||
| CVE-2024-27507 | 2 Fedoraproject, Liblas | 2 Fedora, Liblas | 2026-06-17 | N/A | 7.5 HIGH |
| libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp. | |||||
| CVE-2024-27499 | 1 Webkul | 1 Bagisto | 2026-06-17 | N/A | 6.5 MEDIUM |
| Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. | |||||
| CVE-2024-27497 | 1 Linksys | 2 E2000, E2000 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file. | |||||
| CVE-2024-27489 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request. | |||||
| CVE-2024-27488 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default. | |||||
| CVE-2024-27480 | 1 Vvveb | 1 Vvvebjs | 2026-06-17 | N/A | 9.8 CRITICAL |
| givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. | |||||
| CVE-2024-27477 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 6.1 MEDIUM |
| In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks. | |||||
| CVE-2024-27476 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 4.7 MEDIUM |
| Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket. | |||||
| CVE-2024-27474 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 8.8 HIGH |
| Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators. | |||||
| CVE-2024-27461 | 1 Intel | 1 Memory And Storage Tool Gui | 2026-06-17 | N/A | 5.6 MEDIUM |
| Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access. | |||||
| CVE-2024-27460 | 1 Hp | 1 Poly Plantronics Hub | 2026-06-17 | N/A | 6.7 MEDIUM |
| A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below. | |||||
| CVE-2024-27459 | 1 Openvpn | 1 Openvpn | 2026-06-17 | N/A | 7.8 HIGH |
| The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges. | |||||
| CVE-2024-27458 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support. | |||||
| CVE-2024-27457 | 2026-06-17 | N/A | 2.5 LOW | ||
| Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access. | |||||
| CVE-2024-27456 | 1 Rylabs | 1 Rack Cors Middleware | 2026-06-17 | N/A | 9.1 CRITICAL |
| rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files. | |||||
| CVE-2024-27455 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03. | |||||
| CVE-2024-27454 | 1 Ijl | 1 Orjson | 2026-06-17 | N/A | 7.5 HIGH |
| orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents. | |||||
