Total
396541 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-35495 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic. | |||||
| CVE-2024-35492 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MQTT packet. | |||||
| CVE-2024-35475 | 1 Openkm | 1 Openkm | 2026-06-17 | N/A | 6.4 MEDIUM |
| A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands. | |||||
| CVE-2024-35474 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server, via setPath in ResourcePackFileServer.kt. | |||||
| CVE-2024-35469 | 1 Oretnom23 | 1 Human Resource Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter. | |||||
| CVE-2024-35468 | 1 Oretnom23 | 1 Human Resource Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter. | |||||
| CVE-2024-35451 | 1 Linkstack | 1 Linkstack | 2026-06-17 | N/A | 4.8 MEDIUM |
| LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF. | |||||
| CVE-2024-35434 | 1 Irontec | 1 Sngrep | 2026-06-17 | N/A | 7.5 HIGH |
| Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet. | |||||
| CVE-2024-35433 | 1 Zkteco | 1 Zkbio Cvsecurity | 2026-06-17 | N/A | 8.1 HIGH |
| ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user. | |||||
| CVE-2024-35432 | 1 Zkteco | 1 Zkbio Cvsecurity | 2026-06-17 | N/A | 6.1 MEDIUM |
| ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting. | |||||
| CVE-2024-35431 | 1 Zkteco | 1 Zkbio Cvsecurity | 2026-06-17 | N/A | 7.5 HIGH |
| ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1. | |||||
| CVE-2024-35430 | 1 Zkteco | 1 Zkbio Cvsecurity | 2026-06-17 | N/A | 8.1 HIGH |
| In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application. | |||||
| CVE-2024-35429 | 1 Zkteco | 1 Zkbio Cvsecurity | 2026-06-17 | N/A | 6.5 MEDIUM |
| ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord. | |||||
| CVE-2024-35428 | 1 Zkteco | 1 Zkbio Cvsecurity | 2026-06-17 | N/A | 7.1 HIGH |
| ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS. | |||||
| CVE-2024-35427 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 5.5 MEDIUM |
| vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c. | |||||
| CVE-2024-35426 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 9.8 CRITICAL |
| vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c. | |||||
| CVE-2024-35425 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 5.5 MEDIUM |
| vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c. | |||||
| CVE-2024-35424 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 5.5 MEDIUM |
| vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c. | |||||
| CVE-2024-35423 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 7.8 HIGH |
| vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c. | |||||
| CVE-2024-35422 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 7.8 HIGH |
| vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c. | |||||
