Vulnerabilities (CVE)

Total 395598 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-58258 2026-06-17 N/A 7.2 HIGH
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
CVE-2024-58257 1 Huawei 2 Enzoh-w5611t, Enzoh-w5611t Firmware 2026-06-17 N/A 5.7 MEDIUM
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
CVE-2024-58256 1 Huawei 2 Enzoh-w5611t, Enzoh-w5611t Firmware 2026-06-17 N/A 4.5 MEDIUM
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
CVE-2024-58255 1 Huawei 2 Enzoh-w5611t, Enzoh-w5611t Firmware 2026-06-17 N/A 5.0 MEDIUM
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
CVE-2024-58253 2026-06-17 N/A 2.9 LOW
In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.
CVE-2024-58252 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-58251 2026-06-17 N/A 2.5 LOW
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
CVE-2024-58250 2026-06-17 N/A 9.3 CRITICAL
The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
CVE-2024-58249 2026-06-17 N/A 3.7 LOW
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.
CVE-2024-58248 1 Nopcommerce 1 Nopcommerce 2026-06-17 N/A 3.5 LOW
nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.
CVE-2024-58136 1 Yiiframework 1 Yii 2026-06-17 N/A 9.0 CRITICAL
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
CVE-2024-58135 1 Mojolicious 1 Mojolicious 2026-06-17 N/A 5.3 MEDIUM
Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default. When creating a default app skeleton with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and used for authenticating and protecting the integrity of the application's sessions. This may allow an attacker to brute force the application's session keys. Release 9.46 fixes the issue by providing high quality randomness, even in absence of CryptX. Users should be aware that the update does not replace previously generated weak secrets. A secret generated with the previous version MUST be replaced to ensure the updated version is using a strong secret.
CVE-2024-58134 1 Mojolicious 1 Mojolicious 2026-06-17 N/A 8.1 HIGH
Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies.  An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.
CVE-2024-58133 2026-06-17 N/A 4.0 MEDIUM
In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a map are mishandled. Creating other logs simultaneously can lead to a read-write conflict and panic.
CVE-2024-58132 2026-06-17 N/A 4.0 MEDIUM
In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal nodes to perform concurrent read and write operations on a map, leading to a panic.
CVE-2024-58131 1 Fisco-bcos 1 Fisco-bcos 2026-06-17 N/A 4.0 MEDIUM
FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a large min_seal_time value) joins a blockchain network.
CVE-2024-58127 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 8.4 HIGH
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
CVE-2024-58126 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 8.4 HIGH
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
CVE-2024-58125 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 8.4 HIGH
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
CVE-2024-58124 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 8.4 HIGH
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.