Vulnerabilities (CVE)

Total 395957 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40462 1 Ocuco 1 Innovation 2026-06-17 N/A 7.8 HIGH
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component
CVE-2024-40461 1 Ocuco 1 Innovation 2026-06-17 N/A 7.8 HIGH
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component
CVE-2024-40460 1 Ocuco 1 Innovation 2026-06-17 N/A 7.8 HIGH
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
CVE-2024-40459 1 Ocuco 1 Innovation 2026-06-17 N/A 7.8 HIGH
An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function
CVE-2024-40458 1 Ocuco 1 Innovation 2026-06-17 N/A 7.8 HIGH
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.
CVE-2024-40457 2026-06-17 N/A 9.1 CRITICAL
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.
CVE-2024-40456 1 Thinksaas 1 Thinksaas 2026-06-17 N/A 9.8 CRITICAL
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.
CVE-2024-40455 1 Thinksaas 1 Thinksaas 2026-06-17 N/A 2.7 LOW
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.
CVE-2024-40453 1 Squirrelly 1 Squirrelly 2026-06-17 N/A 9.8 CRITICAL
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.
CVE-2024-40446 1 Ctan 1 Mimetex 2026-06-17 N/A 9.8 CRITICAL
An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
CVE-2024-40445 1 Ctan 1 Mimetex 2026-06-17 N/A 7.3 HIGH
A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.
CVE-2024-40443 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 4.3 MEDIUM
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
CVE-2024-40442 2026-06-17 N/A 7.2 HIGH
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.
CVE-2024-40441 2026-06-17 N/A 6.6 MEDIUM
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.
CVE-2024-40433 1 Tencent 1 Wechat 2026-06-17 N/A 8.8 HIGH
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.
CVE-2024-40432 2026-06-17 N/A 6.5 MEDIUM
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SFFDISK_DEVICE_COMMAND control of the SD card reader driver allows a privileged attacker to crash the OS.
CVE-2024-40431 2026-06-17 N/A 8.8 HIGH
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user.
CVE-2024-40427 1 Dronecode 1 Px4 Drone Autopilot 2026-06-17 N/A 7.9 HIGH
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute
CVE-2024-40425 1 Sparkshop 1 Sparkshop 2026-06-17 N/A 9.8 CRITICAL
File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.
CVE-2024-40422 1 Stitionai 1 Devika 2026-06-17 N/A 9.1 CRITICAL
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.