Total
398466 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-24276 | 1 Teamwire | 1 Teamwire | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components. | |||||
| CVE-2024-24275 | 2 Microsoft, Teamwire | 2 Windows, Teamwire | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. | |||||
| CVE-2024-24272 | 1 Itopvpn | 1 Dualsafe Password Manager | 2026-06-17 | N/A | 7.1 HIGH |
| An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret. | |||||
| CVE-2024-24267 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 7.5 HIGH |
| gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function. | |||||
| CVE-2024-24266 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 7.5 HIGH |
| gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c. | |||||
| CVE-2024-24265 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 7.5 HIGH |
| gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function. | |||||
| CVE-2024-24263 | 1 Chendotjs | 1 Lotos Webserver | 2026-06-17 | N/A | 7.5 HIGH |
| Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c. | |||||
| CVE-2024-24262 | 1 Ireader | 1 Media-server | 2026-06-17 | N/A | 7.5 HIGH |
| media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c. | |||||
| CVE-2024-24260 | 1 Ireader | 1 Media-server | 2026-06-17 | N/A | 7.5 HIGH |
| media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c. | |||||
| CVE-2024-24259 | 1 Artifex | 1 Mupdf | 2026-06-17 | N/A | 7.5 HIGH |
| freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. | |||||
| CVE-2024-24258 | 1 Artifex | 1 Mupdf | 2026-06-17 | N/A | 7.5 HIGH |
| freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. | |||||
| CVE-2024-24257 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component. | |||||
| CVE-2024-24256 | 1 Yonyou | 1 Yonyou | 2026-06-17 | N/A | 5.9 MEDIUM |
| SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory. | |||||
| CVE-2024-24255 | 1 Dronecode | 1 Px4 Drone Autopilot | 2026-06-17 | N/A | 4.2 MEDIUM |
| A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions. | |||||
| CVE-2024-24254 | 1 Dronecode | 1 Px4 Drone Autopilot | 2026-06-17 | N/A | 4.2 MEDIUM |
| PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes. | |||||
| CVE-2024-24246 | 2 Fedoraproject, Qpdf Project | 2 Fedora, Qpdf | 2026-06-17 | N/A | 5.5 MEDIUM |
| Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h. | |||||
| CVE-2024-24245 | 1 Clamxav | 1 Clamxav | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component. | |||||
| CVE-2024-24230 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command. | |||||
| CVE-2024-24216 | 1 Easycorp | 1 Zentao | 2026-06-17 | N/A | 9.8 CRITICAL |
| Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php. | |||||
| CVE-2024-24215 | 1 Cellinx | 1 Nvt Web Server | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request. | |||||
