Vulnerabilities (CVE)

Total 398387 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-27516 1 Livehelperchat 1 Live Helper Chat 2026-06-17 N/A 9.8 CRITICAL
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
CVE-2024-27515 1 Mindstellar 1 Osclass 2026-06-17 N/A 7.2 HIGH
Osclass 5.1.2 is vulnerable to SQL Injection.
CVE-2024-27508 1 Atheme 1 Atheme 2026-06-17 N/A 7.5 HIGH
Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.
CVE-2024-27507 2 Fedoraproject, Liblas 2 Fedora, Liblas 2026-06-17 N/A 7.5 HIGH
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
CVE-2024-27499 1 Webkul 1 Bagisto 2026-06-17 N/A 6.5 MEDIUM
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
CVE-2024-27497 1 Linksys 2 E2000, E2000 Firmware 2026-06-17 N/A 8.8 HIGH
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
CVE-2024-27489 2026-06-17 N/A 7.5 HIGH
An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.
CVE-2024-27488 2026-06-17 N/A 9.8 CRITICAL
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.
CVE-2024-27480 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 9.8 CRITICAL
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
CVE-2024-27477 1 Leantime 1 Leantime 2026-06-17 N/A 6.1 MEDIUM
In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks.
CVE-2024-27476 1 Leantime 1 Leantime 2026-06-17 N/A 4.7 MEDIUM
Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
CVE-2024-27474 1 Leantime 1 Leantime 2026-06-17 N/A 8.8 HIGH
Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.
CVE-2024-27461 1 Intel 1 Memory And Storage Tool Gui 2026-06-17 N/A 5.6 MEDIUM
Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service via local access.
CVE-2024-27460 1 Hp 1 Poly Plantronics Hub 2026-06-17 N/A 6.7 MEDIUM
A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.
CVE-2024-27459 1 Openvpn 1 Openvpn 2026-06-17 N/A 7.8 HIGH
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
CVE-2024-27458 2026-06-17 N/A 8.8 HIGH
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.
CVE-2024-27457 2026-06-17 N/A 2.5 LOW
Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access.
CVE-2024-27456 1 Rylabs 1 Rack Cors Middleware 2026-06-17 N/A 9.1 CRITICAL
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
CVE-2024-27455 2026-06-17 N/A 9.1 CRITICAL
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.
CVE-2024-27454 1 Ijl 1 Orjson 2026-06-17 N/A 7.5 HIGH
orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.