Total
396511 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-36066 | 1 Keyfactor | 1 Ejbca | 2026-06-17 | N/A | 3.1 LOW |
| The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CMP includes password-based MAC as one of the options for message integrity and authentication (the other option is certificate-based). RFC 4211 section 4.4 requires that password-based MAC parameters use a salt with a random value of at least 8 octets. This helps to inhibit dictionary attacks. Because the standalone CMP client originally was developed as test code, the salt was instead hardcoded and only 6 octets long. | |||||
| CVE-2024-36064 | 2026-06-17 | N/A | 6.2 MEDIUM | ||
| The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.nll.cb.dialer.dialer.DialerActivity component. | |||||
| CVE-2024-36063 | 2026-06-17 | N/A | 7.5 HIGH | ||
| The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component. | |||||
| CVE-2024-36062 | 2026-06-17 | N/A | 4.0 MEDIUM | ||
| The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component. | |||||
| CVE-2024-36061 | 1 Engeniustech | 2 Ews356-fit, Ews356-fit Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities. | |||||
| CVE-2024-36060 | 2026-06-17 | N/A | 8.8 HIGH | ||
| EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters. | |||||
| CVE-2024-36059 | 2026-06-17 | N/A | 9.4 CRITICAL | ||
| Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol. | |||||
| CVE-2024-36058 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database. | |||||
| CVE-2024-36057 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data can be controlled by an attacker and is directly included in a system command, i.e., an attack can occur via malicious filenames after uploading a .zip file and clicking Process Images. | |||||
| CVE-2024-36056 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c406490 (for IoAllocateMdl, MmBuildMdlForNonPagedPool, and MmMapLockedPages), leading to NT AUTHORITY\SYSTEM privilege escalation. | |||||
| CVE-2024-36055 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via the MmMapIoSpace API (IOCTL 0x9c40a4f8, 0x9c40a4e8, 0x9c40a4c0, 0x9c40a4c4, 0x9c40a4ec, and seven others), leading to a denial of service (BSOD). | |||||
| CVE-2024-36054 | 2026-06-17 | N/A | 7.4 HIGH | ||
| Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) and IOCTL 0x9c406490 (via ZwMapViewOfSection). | |||||
| CVE-2024-36053 | 2026-06-17 | N/A | 9.0 CRITICAL | ||
| In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file. | |||||
| CVE-2024-36052 | 2 Microsoft, Rarlab | 2 Windows, Winrar | 2026-06-17 | N/A | 7.5 HIGH |
| RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. | |||||
| CVE-2024-36050 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request. | |||||
| CVE-2024-36049 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable information (PII) and especially payroll data and the ability to impersonate legitimate users with respect to the audit log. | |||||
| CVE-2024-36048 | 2 Fedoraproject, Qt | 2 Fedora, Qt | 2026-06-17 | N/A | 9.8 CRITICAL |
| QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values. | |||||
| CVE-2024-36047 | 1 Infoblox | 1 Nios | 2026-06-17 | N/A | 9.8 CRITICAL |
| Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation. | |||||
| CVE-2024-36046 | 1 Infoblox | 1 Nios | 2026-06-17 | N/A | 9.8 CRITICAL |
| Infoblox NIOS through 8.6.4 executes with more privileges than required. | |||||
| CVE-2024-36043 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property. | |||||
