Vulnerabilities (CVE)

Total 395675 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45444 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 5.5 MEDIUM
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-45443 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.1 MEDIUM
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2024-45442 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 5.1 MEDIUM
Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-45441 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-45440 1 Drupal 1 Drupal 2026-06-17 N/A 5.3 MEDIUM
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.
CVE-2024-45438 2026-06-17 N/A 9.1 CRITICAL
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided as part of the email parameter, SpamTitan will automatically create a user record and associate quarantine settings with it - all without requiring authentication.
CVE-2024-45436 1 Ollama 1 Ollama 2026-06-17 N/A 7.5 HIGH
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.
CVE-2024-45435 1 Chartist 1 Chartist 2026-06-17 N/A 9.8 CRITICAL
Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
CVE-2024-45434 1 Opensynergy 1 Blue Sdk 2026-06-17 N/A 9.8 CRITICAL
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of validating the existence of an object before performing operations on the object (aka use after free). An attacker can leverage this to achieve remote code execution in the context of a user account under which the Bluetooth process runs.
CVE-2024-45433 1 Opensynergy 1 Blue Sdk 2026-06-17 N/A 6.5 MEDIUM
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper return control flow after detecting an unusual condition. An attacker can leverage this to bypass a security validation and make the incoming data be processed.
CVE-2024-45432 1 Opensynergy 1 Blue Sdk 2026-06-17 N/A 7.5 HIGH
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain sensitive information.
CVE-2024-45431 1 Opensynergy 1 Blue Sdk 2026-06-17 N/A 5.3 MEDIUM
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper validation of remote L2CAP channel ID (CID). An attacker can leverage this to create an L2CAP channel with the null identifier assigned as a remote CID.
CVE-2024-45429 1 Wpengine 1 Advanced Custom Fields 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's.
CVE-2024-45426 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 4.9 MEDIUM
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
CVE-2024-45425 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 4.9 MEDIUM
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
CVE-2024-45424 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 5.3 MEDIUM
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
CVE-2024-45422 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 6.5 MEDIUM
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial of service via network access.
CVE-2024-45421 1 Zoom 7 Meeting Software Development Kit, Rooms, Rooms Controller and 4 more 2026-06-17 N/A 8.5 HIGH
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
CVE-2024-45420 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2026-06-17 N/A 4.3 MEDIUM
Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a denial of service via network access.
CVE-2024-45419 1 Zoom 7 Meeting Software Development Kit, Rooms, Rooms Controller and 4 more 2026-06-17 N/A 8.1 HIGH
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via network access.