Vulnerabilities (CVE)

Total 395641 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46628 1 Tendacn 2 G3, G3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
CVE-2024-46627 2026-06-17 N/A 9.1 CRITICAL
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
CVE-2024-46626 1 Os4ed 1 Opensis 2026-06-17 N/A 8.8 HIGH
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
CVE-2024-46625 2026-06-17 N/A 8.8 HIGH
An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.
CVE-2024-46624 2026-06-17 N/A 8.8 HIGH
An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.
CVE-2024-46622 2026-06-17 N/A 9.8 CRITICAL
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arbitrary file creation, modification and deletion.
CVE-2024-46613 1 Weechat 1 Weechat 2026-06-17 N/A 9.8 CRITICAL
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_split_tags.
CVE-2024-46612 1 Thecosy 1 Icecms 2026-06-17 N/A 9.8 CRITICAL
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.
CVE-2024-46610 1 Thecosy 1 Icecms 2026-06-17 N/A 7.5 HIGH
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
CVE-2024-46609 1 Thecosy 1 Icecms 2026-06-17 N/A 7.5 HIGH
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
CVE-2024-46603 1 Elspec-ltd 2 G5dfr, G5dfr Firmware 2026-06-17 N/A 7.5 HIGH
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
CVE-2024-46602 1 Elspec-ltd 2 G5dfr, G5dfr Firmware 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.
CVE-2024-46601 1 Elspec-ltd 2 G5dfr, G5dfr Firmware 2026-06-17 N/A 7.5 HIGH
Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.
CVE-2024-46600 1 Timgreen 1 Dingfanzu Cms 2026-06-17 N/A 4.7 MEDIUM
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31
CVE-2024-46598 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2026-06-17 N/A 7.5 HIGH
Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-46597 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2026-06-17 N/A 7.5 HIGH
Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-46596 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2026-06-17 N/A 7.5 HIGH
Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAct parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-46595 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2026-06-17 N/A 7.5 HIGH
Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-46594 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2026-06-17 N/A 7.5 HIGH
Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-46593 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2026-06-17 N/A 7.5 HIGH
Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.