Vulnerabilities (CVE)

Total 395696 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-44459 1 Octavolabs 1 Vernemq 2026-06-17 N/A 7.5 HIGH
A memory allocation issue in vernemq v2.0.1 allows attackers to cause a Denial of Service (DoS) via excessive memory consumption.
CVE-2024-44450 2026-06-17 N/A 5.4 MEDIUM
Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.
CVE-2024-44449 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.
CVE-2024-44439 2026-06-17 N/A 5.9 MEDIUM
An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote attacker to escalate privileges via the open port.
CVE-2024-44430 1 Mayurik 1 Best Free Law Office Management 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface
CVE-2024-44415 2026-06-17 N/A 6.5 MEDIUM
A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.
CVE-2024-44414 2026-06-17 N/A 8.8 HIGH
A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the path parameter can lead to command injection.
CVE-2024-44413 2026-06-17 N/A 8.8 HIGH
A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
CVE-2024-44411 1 Dlink 2 Di-8300, Di-8300 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
CVE-2024-44410 1 Dlink 2 Di-8300, Di-8300 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
CVE-2024-44408 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.
CVE-2024-44402 1 Dlink 2 Di-8100g, Di-8100g Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
CVE-2024-44401 1 Dlink 2 Di-8100g, Di-8100g Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
CVE-2024-44400 1 Dlink 2 Di-8400, Di-8400 Firmware 2026-06-17 N/A 9.8 CRITICAL
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
CVE-2024-44390 1 Tenda 2 Fh1206, Fh1206 Firmware 2026-06-17 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
CVE-2024-44387 1 Tenda 2 Fh1206, Fh1206 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.
CVE-2024-44386 1 Tenda 2 Fh1206, Fh1206 Firmware 2026-06-17 N/A 7.3 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
CVE-2024-44383 1 Wayos 2 Fbm-291w, Fbm-291w Firmware 2026-06-17 N/A 6.8 MEDIUM
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
CVE-2024-44382 1 Dlink 2 Di 8004w, Di 8004w Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
CVE-2024-44381 1 Dlink 2 Di 8004w, Di 8004w Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.