Total
395957 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-40462 | 1 Ocuco | 1 Innovation | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component | |||||
| CVE-2024-40461 | 1 Ocuco | 1 Innovation | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component | |||||
| CVE-2024-40460 | 1 Ocuco | 1 Innovation | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE | |||||
| CVE-2024-40459 | 1 Ocuco | 1 Innovation | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function | |||||
| CVE-2024-40458 | 1 Ocuco | 1 Innovation | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets. | |||||
| CVE-2024-40457 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior. | |||||
| CVE-2024-40456 | 1 Thinksaas | 1 Thinksaas | 2026-06-17 | N/A | 9.8 CRITICAL |
| ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php. | |||||
| CVE-2024-40455 | 1 Thinksaas | 1 Thinksaas | 2026-06-17 | N/A | 2.7 LOW |
| An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request. | |||||
| CVE-2024-40453 | 1 Squirrelly | 1 Squirrelly | 2026-06-17 | N/A | 9.8 CRITICAL |
| squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName. | |||||
| CVE-2024-40446 | 1 Ctan | 1 Mimetex | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script | |||||
| CVE-2024-40445 | 1 Ctan | 1 Mimetex | 2026-06-17 | N/A | 7.3 HIGH |
| A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths. | |||||
| CVE-2024-40443 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2026-06-17 | N/A | 4.3 MEDIUM |
| SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php | |||||
| CVE-2024-40442 | 2026-06-17 | N/A | 7.2 HIGH | ||
| An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request. | |||||
| CVE-2024-40441 | 2026-06-17 | N/A | 6.6 MEDIUM | ||
| An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter. | |||||
| CVE-2024-40433 | 1 Tencent | 1 Wechat | 2026-06-17 | N/A | 8.8 HIGH |
| Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component. | |||||
| CVE-2024-40432 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SFFDISK_DEVICE_COMMAND control of the SD card reader driver allows a privileged attacker to crash the OS. | |||||
| CVE-2024-40431 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user. | |||||
| CVE-2024-40427 | 1 Dronecode | 1 Px4 Drone Autopilot | 2026-06-17 | N/A | 7.9 HIGH |
| Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute | |||||
| CVE-2024-40425 | 1 Sparkshop | 1 Sparkshop | 2026-06-17 | N/A | 9.8 CRITICAL |
| File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component. | |||||
| CVE-2024-40422 | 1 Stitionai | 1 Devika | 2026-06-17 | N/A | 9.1 CRITICAL |
| The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system. | |||||
