Total
395516 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48799 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48798 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48797 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48796 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48795 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48793 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48792 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48791 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process | |||||
| CVE-2024-48790 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process. | |||||
| CVE-2024-48789 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process. | |||||
| CVE-2024-48783 | 1 Ruijie | 2 Nbr3000d-e, Nbr3000d-e Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component. | |||||
| CVE-2024-48782 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end. | |||||
| CVE-2024-48781 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat. | |||||
| CVE-2024-48779 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory. | |||||
| CVE-2024-48766 | 1 Netalertx | 1 Netalertx | 2026-06-17 | N/A | 8.6 HIGH |
| NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php. | |||||
| CVE-2024-48761 | 1 Celk | 1 Celk Saude | 2026-06-17 | N/A | 8.8 HIGH |
| Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter. | |||||
| CVE-2024-48760 | 1 Gestioip | 1 Gestioip | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution. | |||||
| CVE-2024-48758 | 1 Timgreen | 1 Dingfanzu Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code | |||||
| CVE-2024-48747 | 2026-06-17 | N/A | 6.8 MEDIUM | ||
| An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file. | |||||
| CVE-2024-48746 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component | |||||
