Vulnerabilities (CVE)

Total 396541 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35495 2026-06-17 N/A 4.3 MEDIUM
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.
CVE-2024-35492 2026-06-17 N/A 7.5 HIGH
Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MQTT packet.
CVE-2024-35475 1 Openkm 1 Openkm 2026-06-17 N/A 6.4 MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.
CVE-2024-35474 2026-06-17 N/A 6.5 MEDIUM
A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server, via setPath in ResourcePackFileServer.kt.
CVE-2024-35469 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVE-2024-35468 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVE-2024-35451 1 Linkstack 1 Linkstack 2026-06-17 N/A 4.8 MEDIUM
LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
CVE-2024-35434 1 Irontec 1 Sngrep 2026-06-17 N/A 7.5 HIGH
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet.
CVE-2024-35433 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 8.1 HIGH
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.
CVE-2024-35432 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 6.1 MEDIUM
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting.
CVE-2024-35431 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 7.5 HIGH
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
CVE-2024-35430 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 8.1 HIGH
In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.
CVE-2024-35429 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 6.5 MEDIUM
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
CVE-2024-35428 1 Zkteco 1 Zkbio Cvsecurity 2026-06-17 N/A 7.1 HIGH
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.
CVE-2024-35427 1 Lonelycoder 1 Vmir 2026-06-17 N/A 5.5 MEDIUM
vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c.
CVE-2024-35426 1 Lonelycoder 1 Vmir 2026-06-17 N/A 9.8 CRITICAL
vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.
CVE-2024-35425 1 Lonelycoder 1 Vmir 2026-06-17 N/A 5.5 MEDIUM
vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.
CVE-2024-35424 1 Lonelycoder 1 Vmir 2026-06-17 N/A 5.5 MEDIUM
vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.
CVE-2024-35423 1 Lonelycoder 1 Vmir 2026-06-17 N/A 7.8 HIGH
vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.
CVE-2024-35422 1 Lonelycoder 1 Vmir 2026-06-17 N/A 7.8 HIGH
vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.