Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25565 2026-06-17 N/A 3.8 LOW
Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access.
CVE-2024-25563 1 Intel 14 Killer, Killer Wi-fi 6 Ax1650, Killer Wi-fi 6e Ax1675 and 11 more 2026-06-17 N/A 3.4 LOW
Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before version 23.40 may allow a privileged user to potentially enable information disclosure via local access.
CVE-2024-25562 1 Intel 2 Distribution For Gdb, Oneapi Base Toolkit 2026-06-17 N/A 5.8 MEDIUM
Improper buffer restrictions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2024-25561 1 Intel 19 Hid Event Filter Driver, Nuc M15 Laptop Kit Lapbc510, Nuc M15 Laptop Kit Lapbc510 Firmware and 16 more 2026-06-17 N/A 6.7 MEDIUM
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2024-25560 1 F5 22 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 19 more 2026-06-17 N/A 7.5 HIGH
When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2024-25559 1 Appleple 1 A-blog Cms 2026-06-17 N/A 4.7 MEDIUM
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
CVE-2024-25552 1 Wut 3 Com Port Redirector Legacy, Com Port Redirector Plug \& Play, Opc Server 2026-06-17 N/A 7.8 HIGH
A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.
CVE-2024-25551 1 Oretnom23 1 Simple Student Attendance System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.
CVE-2024-25545 1 Weave 1 Weave Desktop 2026-06-17 N/A 7.8 HIGH
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.
CVE-2024-25533 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.4 CRITICAL
Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.
CVE-2024-25532 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.
CVE-2024-25531 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.
CVE-2024-25530 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.
CVE-2024-25529 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.
CVE-2024-25528 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 5.9 MEDIUM
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.
CVE-2024-25527 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.4 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.
CVE-2024-25526 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 8.1 HIGH
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc.aspx.
CVE-2024-25525 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.
CVE-2024-25524 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.4 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.
CVE-2024-25523 1 Ruvar 1 Ruvaroa 2026-06-17 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.