Vulnerabilities (CVE)

Total 395641 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46665 1 Fortinet 1 Fortios 2026-06-17 N/A 3.7 LOW
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.
CVE-2024-46664 1 Fortinet 1 Fortirecorder 2026-06-17 N/A 5.5 MEDIUM
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
CVE-2024-46663 1 Fortinet 1 Fortimail 2026-06-17 N/A 6.7 MEDIUM
A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.
CVE-2024-46662 1 Fortinet 2 Fortimanager, Fortimanager Cloud 2026-06-17 N/A 8.8 HIGH
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets
CVE-2024-46658 2026-06-17 N/A 8.0 HIGH
Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
CVE-2024-46657 1 Artifex 1 Mupdf 2026-06-17 N/A 5.5 MEDIUM
Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2024-46655 1 Ellevo 1 Ellevo 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.
CVE-2024-46654 1 Maccms 1 Maccms 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-46652 1 Tenda 2 Ac8, Ac8 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
CVE-2024-46649 1 Enms 1 Enms 2026-06-17 N/A 7.5 HIGH
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
CVE-2024-46648 1 Enms 1 Enms 2026-06-17 N/A 7.5 HIGH
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
CVE-2024-46647 1 Enms 1 Enms 2026-06-17 N/A 6.5 MEDIUM
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
CVE-2024-46646 1 Enms 1 Enms 2026-06-17 N/A 6.5 MEDIUM
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
CVE-2024-46645 1 Enms 1 Enms 2026-06-17 N/A 7.5 HIGH
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
CVE-2024-46644 1 Enms 1 Enms 2026-06-17 N/A 6.5 MEDIUM
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
CVE-2024-46640 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
CVE-2024-46639 2026-06-17 N/A 7.6 HIGH
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.
CVE-2024-46636 2026-06-17 N/A 9.4 CRITICAL
NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter
CVE-2024-46635 2026-06-17 N/A 5.9 MEDIUM
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.
CVE-2024-46632 1 Assimp 1 Assimp 2026-06-17 N/A 4.3 MEDIUM
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.