Vulnerabilities (CVE)

Total 395652 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46331 1 Modstart 1 Mostartcms 2026-06-17 N/A 7.2 HIGH
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.
CVE-2024-46330 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 7.4 HIGH
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.
CVE-2024-46329 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 8.0 HIGH
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.
CVE-2024-46328 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 8.0 HIGH
VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.
CVE-2024-46327 1 Vonets 2 Vap11g-300, Vap11g-300 Firmware 2026-06-17 N/A 5.7 MEDIUM
An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.
CVE-2024-46326 2026-06-17 N/A 6.1 MEDIUM
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
CVE-2024-46325 1 Tp-link 2 Wr740n, Wr740n Firmware 2026-06-17 N/A 5.5 MEDIUM
TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.
CVE-2024-46316 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 8.0 HIGH
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.
CVE-2024-46313 1 Tp-link 2 Wr941nd, Wr941nd Firmware 2026-06-17 N/A 8.0 HIGH
TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.
CVE-2024-46304 2026-06-17 N/A 7.5 HIGH
A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.
CVE-2024-46300 1 Angeljudesuarez 1 Placement Management System 2026-06-17 N/A 6.1 MEDIUM
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
CVE-2024-46293 1 Oretnom23 1 Online Medicine Ordering System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
CVE-2024-46292 1 Trustwave 1 Modsecurity 2026-06-17 N/A 7.5 HIGH
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).
CVE-2024-46280 2026-06-17 N/A 8.8 HIGH
PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of changing them.
CVE-2024-46278 1 Sismics 1 Teedy 2026-06-17 N/A 8.4 HIGH
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
CVE-2024-46276 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.
CVE-2024-46274 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
CVE-2024-46267 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
CVE-2024-46264 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
CVE-2024-46263 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.