Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25298 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.
CVE-2024-25297 1 Bludit 1 Bludit 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.
CVE-2024-25293 1 Mjml 1 Mjml App 2026-06-17 N/A 9.3 CRITICAL
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
CVE-2024-25292 1 Martinbarker 1 Rendertune 2026-06-17 N/A 9.6 CRITICAL
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter.
CVE-2024-25291 1 Deskfiler 1 Deskfiler 2026-06-17 N/A 9.8 CRITICAL
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
CVE-2024-25290 2026-06-17 N/A 8.0 HIGH
An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.
CVE-2024-25288 1 Slims 1 Senayan Library Management System 2026-06-17 N/A 4.9 MEDIUM
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
CVE-2024-25274 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-25270 1 Mirapolis 1 Lms 2026-06-17 N/A 4.3 MEDIUM
An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.
CVE-2024-25269 1 Struktur 1 Libheif 2026-06-17 N/A 7.5 HIGH
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
CVE-2024-25262 2026-06-17 N/A 8.1 HIGH
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.
CVE-2024-25260 1 Elfutils Project 1 Elfutils 2026-06-17 N/A 4.0 MEDIUM
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
CVE-2024-25255 2026-06-17 N/A 9.8 CRITICAL
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.
CVE-2024-25254 1 Mcafee 1 Superscan 2026-06-17 N/A 9.8 CRITICAL
SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.
CVE-2024-25253 2026-06-17 N/A 7.5 HIGH
Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.
CVE-2024-25251 1 Carmelo 1 Agro-school Management System 2026-06-17 N/A 8.8 HIGH
code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
CVE-2024-25250 1 Carmelo 1 Agro-school Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.
CVE-2024-25249 1 He3app 1 He3 App 2026-06-17 N/A 9.8 CRITICAL
An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
CVE-2024-25248 1 Niushop 1 B2b2c Multi-business 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
CVE-2024-25247 1 Niushop 1 B2b2c Multi-business 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.