Vulnerabilities (CVE)

Total 395563 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57724 1 Sammycage 1 Lunasvg 2026-06-17 N/A 6.5 MEDIUM
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.
CVE-2024-57723 1 Sammycage 1 Lunasvg 2026-06-17 N/A 6.5 MEDIUM
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
CVE-2024-57722 1 Sammycage 1 Lunasvg 2026-06-17 N/A 7.5 HIGH
lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.
CVE-2024-57721 1 Sammycage 1 Lunasvg 2026-06-17 N/A 6.5 MEDIUM
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
CVE-2024-57720 1 Sammycage 1 Lunasvg 2026-06-17 N/A 6.5 MEDIUM
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
CVE-2024-57719 1 Sammycage 1 Lunasvg 2026-06-17 N/A 6.5 MEDIUM
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.
CVE-2024-57716 2026-06-17 N/A 7.5 HIGH
An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.
CVE-2024-57708 2026-06-17 N/A 5.7 MEDIUM
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.
CVE-2024-57707 1 Dataease 1 Dataease 2026-06-17 N/A 9.8 CRITICAL
An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
CVE-2024-57704 1 Tenda 2 Ac8, Ac8 Firmware 2026-06-17 N/A 8.8 HIGH
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow.
CVE-2024-57703 1 Tenda 2 Ac8, Ac8 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.
CVE-2024-57699 2026-06-17 N/A 7.5 HIGH
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
CVE-2024-57698 1 Modernwms 1 Modernwms 2026-06-17 N/A 7.5 HIGH
An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.
CVE-2024-57695 1 Opswat 1 Outpost Security Suite 2026-06-17 N/A 7.7 HIGH
An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer fixed the vulnerability in version 8.0 (4164.652.1856) from December 17, 2012.
CVE-2024-57687 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 9.8 CRITICAL
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.
CVE-2024-57686 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 9.8 CRITICAL
A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter.
CVE-2024-57685 1 Sparkshop 1 Sparkshop 2026-06-17 N/A 5.3 MEDIUM
An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
CVE-2024-57684 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 9.8 CRITICAL
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
CVE-2024-57683 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 4.3 MEDIUM
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.
CVE-2024-57682 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 6.5 MEDIUM
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.