Vulnerabilities (CVE)

Total 396388 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38309 2026-06-17 N/A 7.8 HIGH
There are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier), TELLUS (v4.0.19.0 and earlier), and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
CVE-2024-38308 1 Advantech 2 Adam-5550, Adam 5550-firmware 2026-06-17 N/A 8.8 HIGH
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.
CVE-2024-38307 2026-06-17 N/A 7.7 HIGH
Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authenticated user to potentially enable denial of service via network access.
CVE-2024-38305 1 Dell 1 Supportassist For Home Pcs 2026-06-17 N/A 7.3 HIGH
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges.
CVE-2024-38304 1 Dell 62 Dss 8440, Dss 8440 Firmware, Emc Storage Nx3240 and 59 more 2026-06-17 N/A 3.8 LOW
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2024-38303 1 Dell 62 Dss 8440, Dss 8440 Firmware, Emc Storage Nx3240 and 59 more 2026-06-17 N/A 5.3 MEDIUM
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2024-38302 1 Dell 1 Data Lakehouse 2026-06-17 N/A 6.8 MEDIUM
Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2024-38301 1 Dell 1 Alienware Command Center 2026-06-17 N/A 6.7 MEDIUM
Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privileged attacker could potentially exploit this vulnerability, leading to denial of service on the local system and information disclosure.
CVE-2024-38296 1 Dell 3 Edge Gateway 3200, Edge Gateway 5200, Intel Management Engine Firmware Update Utility 2026-06-17 N/A 6.7 MEDIUM
Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
CVE-2024-38295 1 Alcasar 1 Alcasar 2026-06-17 N/A 9.8 CRITICAL
ALCASAR before 3.6.1 allows still_connected.php remote code execution.
CVE-2024-38294 1 Alcasar 1 Alcasar 2026-06-17 N/A 9.8 CRITICAL
ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.
CVE-2024-38293 1 Alcasar 1 Alcasar 2026-06-17 N/A 9.6 CRITICAL
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
CVE-2024-38292 1 Extremenetworks 1 Xiq-se 2026-06-17 N/A 9.8 CRITICAL
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.
CVE-2024-38291 1 Extremenetworks 1 Xiq-se 2026-06-17 N/A 8.8 HIGH
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.
CVE-2024-38290 1 Extremenetworks 1 Xiq-se 2026-06-17 N/A 5.3 MEDIUM
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
CVE-2024-38289 1 Rhubcom 1 Turbomeeting 2026-06-17 N/A 9.8 CRITICAL
A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.
CVE-2024-38288 1 Rhubcom 1 Turbomeeting 2026-06-17 N/A 7.2 HIGH
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.
CVE-2024-38287 1 Rhubcom 1 Turbomeeting 2026-06-17 N/A 9.8 CRITICAL
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.
CVE-2024-38286 2 Apache, Netapp 2 Tomcat, Ontap Tools 2026-06-17 N/A 8.6 HIGH
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVE-2024-38285 2026-06-17 N/A N/A
Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.