Vulnerabilities (CVE)

Total 396425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36775 1 Monstra 1 Monstra 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.
CVE-2024-36774 1 Monstra 1 Monstra 2026-06-17 N/A 7.2 HIGH
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2024-36773 1 Monstra 1 Monstra 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Themes parameter at index.php.
CVE-2024-36761 1 Gfx-rs 2 Naga, Wgpu 2026-06-17 N/A 9.8 CRITICAL
naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
CVE-2024-36760 2026-06-17 N/A 7.5 HIGH
A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : STMT: : _ $LT $impl $u20 $rhai.. engine.. Engine$GT$::eval_stmt::h3f1d68ce37fc6e96). Due to the stack overflow is a recursive call/SRC/rhai/SRC/eval/STMT. Rs file eval_stmt_block function.
CVE-2024-36755 1 Dlink 2 Dir-1950, Dir-1950 Firmware 2026-06-17 N/A 6.8 MEDIUM
D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.
CVE-2024-36751 2026-06-17 N/A 6.5 MEDIUM
An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL.
CVE-2024-36745 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.index_select parameter.
CVE-2024-36743 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.
CVE-2024-36742 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index parameter exceeds the range of shape.
CVE-2024-36740 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.
CVE-2024-36737 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.
CVE-2024-36736 1 Oneflow 1 Oneflow 2026-06-17 N/A 9.8 CRITICAL
An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed.
CVE-2024-36735 1 Oneflow 1 Oneflow 2026-06-17 N/A 5.3 MEDIUM
OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.
CVE-2024-36734 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the dim parameter.
CVE-2024-36732 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.
CVE-2024-36730 1 Oneflow 1 Oneflow 2026-06-17 N/A 7.5 HIGH
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.
CVE-2024-36729 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 6.3 MEDIUM
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6 with a sufficiently long reboot_type key.
CVE-2024-36728 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 8.1 HIGH
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.
CVE-2024-36694 1 Opencart 1 Opencart 2026-06-17 N/A 7.2 HIGH
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.