Vulnerabilities (CVE)

Total 398466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24213 1 Supabase 1 Postgres 2026-06-17 N/A 9.8 CRITICAL
Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.
CVE-2024-24202 1 Easycorp 3 Zentao, Zentao Biz, Zentao Max 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
CVE-2024-24199 1 Pymumu 1 Smartdns 2026-06-17 N/A 7.5 HIGH
smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.
CVE-2024-24198 1 Pymumu 1 Smartdns 2026-06-17 N/A 7.5 HIGH
smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.
CVE-2024-24195 1 Robertdavidgraham 1 Robdns 2026-06-17 N/A 7.5 HIGH
robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.
CVE-2024-24194 2026-06-17 N/A 7.5 HIGH
robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.
CVE-2024-24192 1 Robertdavidgraham 1 Robdns 2026-06-17 N/A 9.1 CRITICAL
robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.
CVE-2024-24189 1 Jsish 1 Jsish 2026-06-17 N/A 9.8 CRITICAL
Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.
CVE-2024-24188 1 Jsish 1 Jsish 2026-06-17 N/A 9.8 CRITICAL
Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.
CVE-2024-24186 1 Jsish 1 Jsish 2026-06-17 N/A 9.8 CRITICAL
Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.
CVE-2024-24161 1 Mrcms 1 Mrcms 2026-06-17 N/A 7.5 HIGH
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
CVE-2024-24160 1 Mrcms 1 Mrcms 2026-06-17 N/A 5.4 MEDIUM
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.
CVE-2024-24157 1 Sir 1 Gnuboard 2026-06-17 N/A 6.1 MEDIUM
Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.
CVE-2024-24156 1 Sir 1 Gnuboard 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter.
CVE-2024-24155 1 Axiosys 1 Bento4 2026-06-17 N/A 6.5 MEDIUM
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
CVE-2024-24150 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
CVE-2024-24149 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
CVE-2024-24148 1 Libming 1 Libming 2026-06-17 N/A 7.5 HIGH
A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
CVE-2024-24147 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
CVE-2024-24146 1 Libming 1 Libming 2026-06-17 N/A 6.5 MEDIUM
A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.