Vulnerabilities (CVE)

Total 398466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24142 1 Rems 1 School Task Manager 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
CVE-2024-24141 1 Remyandrade 1 School Task Manager 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
CVE-2024-24140 1 Remyandrade 1 Daily Habit Tracker 2026-06-17 N/A 7.2 HIGH
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
CVE-2024-24139 1 Remyandrade 1 Login System With Email Verification 2026-06-17 N/A 7.2 HIGH
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
CVE-2024-24136 1 Remyandrade 1 Math Game 2026-06-17 N/A 6.1 MEDIUM
The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.
CVE-2024-24135 1 Remyandrade 1 Product Inventory With Export To Excel 2026-06-17 N/A 6.1 MEDIUM
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
CVE-2024-24134 1 Remyandrade 1 Online Food Menu 2026-06-17 N/A 4.8 MEDIUM
Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.
CVE-2024-24133 1 Atmail 1 Atmail 2026-06-17 N/A 9.8 CRITICAL
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
CVE-2024-24131 1 Superwebmailer 1 Superwebmailer 2026-06-17 N/A 6.1 MEDIUM
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
CVE-2024-24130 1 Mail2world 1 Mail2world Webmail 2026-06-17 N/A 6.1 MEDIUM
Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.
CVE-2024-24122 1 Wondershare 1 Edraw 2026-06-17 N/A 3.3 LOW
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.
CVE-2024-24117 1 Ruijie 2 Rg-nbs2009g-p, Rg-nbs2009g-p Firmware 2026-06-17 N/A 9.8 CRITICAL
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
CVE-2024-24116 1 Ruijie 2 Rg-nbs2009g-p, Rg-nbs2009g-p Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
CVE-2024-24115 1 Cotonti 1 Cotonti Siena 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-24113 1 Xuxueli 1 Xxl-job 2026-06-17 N/A 8.8 HIGH
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
CVE-2024-24112 1 Exrick 1 Xmall 2026-06-17 N/A 9.8 CRITICAL
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
CVE-2024-24110 1 Crmeb 1 Crmeb Java 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.
CVE-2024-24105 1 Carmelo 1 Computer Science Time Table System 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.
CVE-2024-24101 1 Code-projects 1 Scholars Tracking System 2026-06-17 N/A 9.8 CRITICAL
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
CVE-2024-24100 1 Carmelo 1 Computer Book Store 2026-06-17 N/A 8.3 HIGH
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.