Vulnerabilities (CVE)

Total 398466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24099 1 Code-projects 1 Scholars Tracking System 2026-06-17 N/A 5.4 MEDIUM
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
CVE-2024-24098 1 Fabian 1 Scholars Tracking System 2026-06-17 N/A 7.8 HIGH
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
CVE-2024-24097 1 Code-projects 1 Scholars Tracking System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.
CVE-2024-24096 1 Carmelo 1 Computer Book Store 2026-06-17 N/A 7.8 HIGH
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
CVE-2024-24095 1 Code-projects 1 Simple Stock System 2026-06-17 N/A 9.8 CRITICAL
Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
CVE-2024-24093 1 Code-projects 1 Scholars Tracking System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.
CVE-2024-24092 1 Code-projects 1 Scholars Tracking System 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.
CVE-2024-24091 1 Yealink 1 Yealink Meeting Server 2026-06-17 N/A 9.8 CRITICAL
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
CVE-2024-24062 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
CVE-2024-24061 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
CVE-2024-24060 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
CVE-2024-24059 1 Aitangbao 1 Springboot-manager 2026-06-17 N/A 5.4 MEDIUM
springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.
CVE-2024-24051 1 Monoprice 2 Select Mini 3d Printer V2, Select Mini 3d Printer V2 Firmware 2026-06-17 N/A 5.5 MEDIUM
Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.
CVE-2024-24050 1 Remyandrade 1 Workout Journal App 2026-06-17 N/A 4.7 MEDIUM
Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.
CVE-2024-24043 2026-06-17 N/A 5.5 MEDIUM
Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file.
CVE-2024-24042 2026-06-17 N/A 8.8 HIGH
Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary code via the dumpDirect in RuntimeResourcePackImpl component.
CVE-2024-24041 1 Remyandrade 1 Travel Journal Using Php And Mysql With Source Code 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
CVE-2024-24035 1 Setorinformatica 1 S.i.l. 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.
CVE-2024-24034 1 Setorinformatica 1 S.i.l 2026-06-17 N/A 6.1 MEDIUM
Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.
CVE-2024-24029 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 9.8 CRITICAL
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.