Vulnerabilities (CVE)

Total 396425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36527 2026-06-17 N/A 6.5 MEDIUM
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.
CVE-2024-36526 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 9.8 CRITICAL
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
CVE-2024-36523 1 Wvp-pro 1 Gb28181 2026-06-17 N/A 6.5 MEDIUM
An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.
CVE-2024-36522 1 Apache 1 Wicket 2026-06-17 N/A 9.8 CRITICAL
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to versions 10.1.0, 9.18.0 or 8.16.0, which fix this issue.
CVE-2024-36518 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.
CVE-2024-36517 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
CVE-2024-36516 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.
CVE-2024-36515 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.
CVE-2024-36514 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.
CVE-2024-36513 1 Fortinet 1 Forticlient 2026-06-17 N/A 8.2 HIGH
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
CVE-2024-36512 1 Fortinet 2 Fortianalyzer, Fortimanager 2026-06-17 N/A 7.2 HIGH
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
CVE-2024-36511 1 Fortinet 1 Fortiadc 2026-06-17 N/A 3.7 LOW
An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions when cookie security policy is enabled may allow an attacker, under specific conditions, to retrieve the initial encrypted and signed cookie protected by the feature
CVE-2024-36510 1 Fortinet 2 Forticlientems, Fortisoar 2026-06-17 N/A 5.3 MEDIUM
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
CVE-2024-36509 1 Fortinet 1 Fortiweb 2026-06-17 N/A 4.2 MEDIUM
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, version 7.0.10 and below, version 6.3.23 and below may allow an authenticated attacker to access the encrypted passwords of other administrators via the "Log Access Event" logs page.
CVE-2024-36508 1 Fortinet 2 Fortianalyzer, Fortimanager 2026-06-17 N/A 6.0 MEDIUM
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to delete files on the system.
CVE-2024-36507 1 Fortinet 1 Forticlient 2026-06-17 N/A 7.3 HIGH
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
CVE-2024-36506 1 Fortinet 2 Forticlientems, Forticlientems Cloud 2026-06-17 N/A 3.7 LOW
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.
CVE-2024-36505 1 Fortinet 1 Fortios 2026-06-17 N/A 5.1 MEDIUM
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
CVE-2024-36504 1 Fortinet 1 Fortios 2026-06-17 N/A 6.5 MEDIUM
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web portal via a specially crafted URL.
CVE-2024-36503 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 7.3 HIGH
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.