Total
396474 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-36466 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 8.8 HIGH |
| A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions. | |||||
| CVE-2024-36465 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 8.8 HIGH |
| A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter. | |||||
| CVE-2024-36464 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 2.7 LOW |
| When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords. | |||||
| CVE-2024-36463 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 6.5 MEDIUM |
| The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects. | |||||
| CVE-2024-36462 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 7.5 HIGH |
| Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance of the affected system. | |||||
| CVE-2024-36461 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 9.1 CRITICAL |
| Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | |||||
| CVE-2024-36460 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 8.1 HIGH |
| The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. | |||||
| CVE-2024-36459 | 2026-06-17 | N/A | N/A | ||
| A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser. | |||||
| CVE-2024-36458 | 2026-06-17 | N/A | N/A | ||
| The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions. | |||||
| CVE-2024-36457 | 2026-06-17 | N/A | N/A | ||
| The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint. | |||||
| CVE-2024-36456 | 2026-06-17 | N/A | N/A | ||
| This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file. | |||||
| CVE-2024-36455 | 2026-06-17 | N/A | N/A | ||
| An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request. | |||||
| CVE-2024-36454 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is exploited, the system may be rebooted or suspended by receiving a specially crafted packet. | |||||
| CVE-2024-36453 | 1 Webmin | 2 Usermin, Webmin | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions prior to 1.820. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a webpage may be altered or sensitive information such as a credential may be disclosed. | |||||
| CVE-2024-36452 | 1 Webmin | 1 Webmin | 2026-06-17 | N/A | 3.1 LOW |
| Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when a user views a malicious page while logged in. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted. | |||||
| CVE-2024-36451 | 1 Webmin | 1 Webmin | 2026-06-17 | N/A | 8.8 HIGH |
| Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session may be hijacked by an unauthorized user. As a result, data within a system may be referred, a webpage may be altered, or a server may be permanently halted. | |||||
| CVE-2024-36450 | 1 Webmin | 1 Webmin | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted. | |||||
| CVE-2024-36448 | 1 Apache | 1 Iotdb Workbench | 2026-06-17 | N/A | 7.3 HIGH |
| ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2024-36446 | 1 Mitel | 1 Mivoice Mx-one | 2026-06-17 | N/A | 8.8 HIGH |
| The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema. | |||||
| CVE-2024-36445 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication. | |||||
