Vulnerabilities (CVE)

Total 395957 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40519 1 Seacms 1 Seacms 2026-06-17 N/A 8.8 HIGH
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
CVE-2024-40518 1 Seacms 1 Seacms 2026-06-17 N/A 8.8 HIGH
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing and writing the user input data into weixin.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions.
CVE-2024-40516 2026-06-17 N/A 8.8 HIGH
An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing functionality.
CVE-2024-40515 1 Tenda 2 Ax2 Pro, Ax2 Pro Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.
CVE-2024-40514 1 Themesbrand 1 Chatvia 2026-06-17 N/A 4.6 MEDIUM
Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via the User profile name and image upload functions.
CVE-2024-40513 1 Themesbrand 1 Chatvia 2026-06-17 N/A 4.6 MEDIUM
An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function.
CVE-2024-40512 1 Openpetra 1 Openpetra 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.
CVE-2024-40511 1 Openpetra 1 Openpetra 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.
CVE-2024-40510 1 Openpetra 1 Openpetra 2026-06-17 N/A 8.2 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.
CVE-2024-40509 1 Openpetra 1 Openpetra 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.
CVE-2024-40508 1 Openpetra 1 Openpetra 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.
CVE-2024-40507 1 Openpetra 1 Openpetra 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.
CVE-2024-40506 1 Openpetra 1 Openpetra 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.
CVE-2024-40505 1 Dlink 2 Dap-1650, Dap-1650 Firmware 2026-06-17 N/A 9.3 CRITICAL
Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.
CVE-2024-40503 1 Tenda 2 Ax12, Ax12 Firmware 2026-06-17 N/A 6.5 MEDIUM
An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.
CVE-2024-40502 1 Angeljudesuarez 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx
CVE-2024-40500 1 Scilico 1 I\, Librarian 2026-06-17 N/A 8.6 HIGH
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.
CVE-2024-40498 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php
CVE-2024-40494 1 Keith-cullen 1 Freecoap 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.
CVE-2024-40493 1 Keith-cullen 1 Freecoap 2026-06-17 N/A 9.8 CRITICAL
Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code via a specially crafted CoAP packet that causes `coap_msg_get_payload(resp)` to return a null pointer, which is then dereferenced in a call to `memcpy`.