Total
258583 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-34274 | 2024-07-03 | N/A | 3.9 LOW | ||
| OpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD software uses serialized data, which can be used to execute arbitrary code on the system. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2024-34256 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | |||||
| CVE-2024-34255 | 2024-07-03 | N/A | 6.1 MEDIUM | ||
| jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function. | |||||
| CVE-2024-34251 | 2024-07-03 | N/A | 7.5 HIGH | ||
| An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | |||||
| CVE-2024-34250 | 2024-07-03 | N/A | 6.2 MEDIUM | ||
| A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c. | |||||
| CVE-2024-34249 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c. | |||||
| CVE-2024-34246 | 2024-07-03 | N/A | 7.5 HIGH | ||
| wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c. | |||||
| CVE-2024-34244 | 2024-07-03 | N/A | 7.5 HIGH | ||
| libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors. | |||||
| CVE-2024-34241 | 2024-07-03 | N/A | 4.8 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications. | |||||
| CVE-2024-34225 | 2024-07-03 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters. | |||||
| CVE-2024-34222 | 2024-07-03 | N/A | 5.9 MEDIUM | ||
| Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter. | |||||
| CVE-2024-34221 | 2024-07-03 | N/A | 8.8 HIGH | ||
| Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation. | |||||
| CVE-2024-34220 | 2024-07-03 | N/A | 7.5 HIGH | ||
| Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter. | |||||
| CVE-2024-34218 | 2024-07-03 | N/A | 3.8 LOW | ||
| TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. | |||||
| CVE-2024-34215 | 2024-07-03 | N/A | 7.3 HIGH | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function. | |||||
| CVE-2024-34213 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function. | |||||
| CVE-2024-34212 | 2024-07-03 | N/A | 7.3 HIGH | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function. | |||||
| CVE-2024-34210 | 2024-07-03 | N/A | 7.3 HIGH | ||
| TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter. | |||||
| CVE-2024-34209 | 2024-07-03 | N/A | 9.8 CRITICAL | ||
| TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function. | |||||
| CVE-2024-34206 | 2024-07-03 | N/A | 6.5 MEDIUM | ||
| TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. | |||||
