Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25298 | 1 Redaxo | 1 Redaxo | 2026-06-17 | N/A | 7.2 HIGH |
| An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php. | |||||
| CVE-2024-25297 | 1 Bludit | 1 Bludit | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php. | |||||
| CVE-2024-25293 | 1 Mjml | 1 Mjml App | 2026-06-17 | N/A | 9.3 CRITICAL |
| mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute. | |||||
| CVE-2024-25292 | 1 Martinbarker | 1 Rendertune | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter. | |||||
| CVE-2024-25291 | 1 Deskfiler | 1 Deskfiler | 2026-06-17 | N/A | 9.8 CRITICAL |
| Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin. | |||||
| CVE-2024-25290 | 2026-06-17 | N/A | 8.0 HIGH | ||
| An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function. | |||||
| CVE-2024-25288 | 1 Slims | 1 Senayan Library Management System | 2026-06-17 | N/A | 4.9 MEDIUM |
| SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. | |||||
| CVE-2024-25274 | 1 Xxyopen | 1 Novel-plus | 2026-06-17 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-25270 | 1 Mirapolis | 1 Lms | 2026-06-17 | N/A | 4.3 MEDIUM |
| An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data. | |||||
| CVE-2024-25269 | 1 Struktur | 1 Libheif | 2026-06-17 | N/A | 7.5 HIGH |
| libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack. | |||||
| CVE-2024-25262 | 2026-06-17 | N/A | 8.1 HIGH | ||
| texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file. | |||||
| CVE-2024-25260 | 1 Elfutils Project | 1 Elfutils | 2026-06-17 | N/A | 4.0 MEDIUM |
| elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. | |||||
| CVE-2024-25255 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior. | |||||
| CVE-2024-25254 | 1 Mcafee | 1 Superscan | 2026-06-17 | N/A | 9.8 CRITICAL |
| SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter. | |||||
| CVE-2024-25253 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module. | |||||
| CVE-2024-25251 | 1 Carmelo | 1 Agro-school Management System | 2026-06-17 | N/A | 8.8 HIGH |
| code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control. | |||||
| CVE-2024-25250 | 1 Carmelo | 1 Agro-school Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page. | |||||
| CVE-2024-25249 | 1 He3app | 1 He3 App | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. | |||||
| CVE-2024-25248 | 1 Niushop | 1 B2b2c Multi-business | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter. | |||||
| CVE-2024-25247 | 1 Niushop | 1 B2b2c Multi-business | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters. | |||||
