Vulnerabilities (CVE)

Total 398901 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-0324 1 Cozmoslabs 1 Profile Builder 2026-06-17 N/A 8.2 HIGH
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.
CVE-2024-0323 1 Br-automation 1 Automation Runtime 2026-06-17 N/A 9.8 CRITICAL
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.
CVE-2024-0322 1 Gpac 1 Gpac 2026-06-17 N/A 9.1 CRITICAL
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2024-0321 1 Gpac 1 Gpac 2026-06-17 N/A 9.8 CRITICAL
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2024-0320 1 Fireeye 1 Malware Analysis 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application URL to retrieve the session details of a legitimate user.
CVE-2024-0319 1 Fireeye 1 Hxtool 2026-06-17 N/A 5.4 MEDIUM
Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious page by changing the 'redirect_uri' parameter.
CVE-2024-0318 1 Fireeye 1 Hxtool 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and 'Hostname/IP' parameters that will be triggered when items are loaded.
CVE-2024-0317 1 Fireeye 6 Ex 3500, Ex 3500 Firmware, Ex 5500 and 3 more 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.
CVE-2024-0316 1 Fireeye 1 Endpoint Security 2026-06-17 N/A 6.8 MEDIUM
Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage.
CVE-2024-0315 1 Fireeye 1 Central Management 2026-06-17 N/A 6.6 MEDIUM
Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system during the report creation process.
CVE-2024-0314 1 Fireeye 1 Central Management 2026-06-17 N/A 5.4 MEDIUM
XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking.
CVE-2024-0313 2026-06-17 N/A 5.5 MEDIUM
A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately using the temporary bypass to reach out to the Internet for retrieving application and system updates, a remote device could target it and undo the bypass, thereby denying the victim access to the update service, causing it to fail.
CVE-2024-0312 2026-06-17 N/A 5.5 MEDIUM
A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
CVE-2024-0311 2026-06-17 N/A 5.5 MEDIUM
A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.
CVE-2024-0310 2 Microsoft, Trellix 2 Windows, Endpoint Security Web Control 2026-06-17 N/A 6.1 MEDIUM
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
CVE-2024-0308 1 Inis Project 1 Inis 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Inis up to 2.0.1. It has been rated as critical. This issue affects some unknown processing of the file app/api/controller/default/Proxy.php. The manipulation of the argument p_url leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249875.
CVE-2024-0307 1 Lopalopa 1 Dynamic Lab Management System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249874 is the identifier assigned to this vulnerability.
CVE-2024-0306 1 Lopalopa 1 Dynamic Lab Management System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249873 was assigned to this vulnerability.
CVE-2024-0305 1 Ncast Project 1 Ncast 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.
CVE-2024-0304 1 Youke365 1 Youke 365 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/collect.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249871.