Vulnerabilities (CVE)

Total 395648 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46546 1 Nextu 2 Fleta Ax1500, Fleta Ax1500 Firmware 2026-06-17 N/A 7.3 HIGH
NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-46544 2 Apache, Debian 2 Tomcat Connectors, Debian Linux 2026-06-17 N/A 5.9 MEDIUM
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.
CVE-2024-46542 2026-06-17 N/A 6.5 MEDIUM
Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.
CVE-2024-46540 1 Emlog 1 Emlog 2026-06-17 N/A 6.3 MEDIUM
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.
CVE-2024-46539 2026-06-17 N/A 8.2 HIGH
Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).
CVE-2024-46538 1 Netgate 1 Pfsense 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
CVE-2024-46535 1 Ketr 1 Jepaas 2026-06-17 N/A 9.8 CRITICAL
Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.
CVE-2024-46531 1 Phpgurukul 1 Vehicle Record System 2026-06-17 N/A 6.3 MEDIUM
phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.
CVE-2024-46528 2026-06-17 N/A 4.3 MEDIUM
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.
CVE-2024-46511 2026-06-17 N/A 7.5 HIGH
LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLambda and CredsGenFunction function.
CVE-2024-46510 1 Esafenet 1 Cdg 2026-06-17 N/A 7.6 HIGH
ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface
CVE-2024-46508 1 Yeti-platform 1 Yeti 2026-06-17 N/A 7.5 HIGH
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
CVE-2024-46507 1 Yeti-platform 1 Yeti 2026-06-17 N/A 7.3 HIGH
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
CVE-2024-46506 1 Netalertx 1 Netalertx 2026-06-17 N/A 10.0 CRITICAL
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.
CVE-2024-46505 2026-06-17 N/A 9.1 CRITICAL
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
CVE-2024-46494 1 Typecho 1 Typecho 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.
CVE-2024-46489 1 Ferrislucas 1 Promptr 2026-06-17 N/A 8.8 HIGH
A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.
CVE-2024-46488 1 Asg017 1 Sqlite-vec 2026-06-17 N/A 5.5 MEDIUM
sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
CVE-2024-46486 1 Tp-link 2 Tl-wdr5620, Tl-wdr5620 Firmware 2026-06-17 N/A 8.0 HIGH
TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.
CVE-2024-46485 1 Timgreen 1 Dingfanzu Cms 2026-06-17 N/A 6.3 MEDIUM
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate