Vulnerabilities (CVE)

Total 396425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36555 2026-06-17 N/A 9.8 CRITICAL
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity of the device.
CVE-2024-36554 2026-06-17 N/A 9.8 CRITICAL
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.
CVE-2024-36553 2026-06-17 N/A 8.1 HIGH
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
CVE-2024-36550 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close
CVE-2024-36549 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close
CVE-2024-36548 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del
CVE-2024-36547 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add
CVE-2024-36542 2026-06-17 N/A 8.8 HIGH
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36541 1 Kube-logging 1 Logging-operator 2026-06-17 N/A 8.8 HIGH
Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36540 1 External-secrets 1 External Secrets Operator 2026-06-17 N/A 9.8 CRITICAL
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36539 1 Projectcontour 1 Contour 2026-06-17 N/A 9.8 CRITICAL
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36538 1 Chaos-mesh 1 Chaos Mesh 2026-06-17 N/A 8.8 HIGH
Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36537 1 Cert-manager 1 Cert-manager 2026-06-17 N/A 7.2 HIGH
Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36536 1 Fabedge 1 Fabedge 2026-06-17 N/A 9.8 CRITICAL
Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36535 1 Layer5 1 Meshery 2026-06-17 N/A 9.8 CRITICAL
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36534 2026-06-17 N/A 8.4 HIGH
Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36533 2026-06-17 N/A 9.8 CRITICAL
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36532 2026-06-17 N/A 10.0 CRITICAL
Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVE-2024-36531 1 Nukeviet 2 Egovernment, Nukeviet 2026-06-17 N/A 5.7 MEDIUM
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.
CVE-2024-36528 1 Nukeviet 2 Egovernment, Nukeviet 2026-06-17 N/A 8.8 HIGH
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.