Total
396541 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-35421 | 1 Lonelycoder | 1 Vmir | 2026-06-17 | N/A | 5.5 MEDIUM |
| vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser.c. | |||||
| CVE-2024-35420 | 1 Kanaka | 1 Wac | 2026-06-17 | N/A | 6.2 MEDIUM |
| wac commit 385e1 was discovered to contain a heap overflow. | |||||
| CVE-2024-35419 | 1 Kanaka | 1 Wac | 2026-06-17 | N/A | 5.5 MEDIUM |
| wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file. | |||||
| CVE-2024-35418 | 1 Kanaka | 1 Wac | 2026-06-17 | N/A | 6.2 MEDIUM |
| wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file. | |||||
| CVE-2024-35410 | 1 Kanaka | 1 Wac | 2026-06-17 | N/A | 6.2 MEDIUM |
| wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file. | |||||
| CVE-2024-35409 | 1 Webidsupport | 1 Webid | 2026-06-17 | N/A | 9.8 CRITICAL |
| WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. | |||||
| CVE-2024-35403 | 1 Totolink | 2 Cp900l, Cp900l Firmware | 2026-06-17 | N/A | 2.7 LOW |
| TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules | |||||
| CVE-2024-35388 | 1 Totolink | 2 Nr1800x, Nr1800x Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode | |||||
| CVE-2024-35387 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth. | |||||
| CVE-2024-35386 | 1 Cesanta | 1 Mjs | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the mjs.c file. | |||||
| CVE-2024-35385 | 1 Cesanta | 1 Mjs | 2026-06-17 | N/A | 4.3 MEDIUM |
| An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file. | |||||
| CVE-2024-35384 | 1 Cesanta | 1 Mjs | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file. | |||||
| CVE-2024-35375 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS | |||||
| CVE-2024-35374 | 1 Mocodo | 1 Mocodo Online | 2026-06-17 | N/A | 9.8 CRITICAL |
| Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions. | |||||
| CVE-2024-35373 | 1 Mocodo | 1 Mocodo Online | 2026-06-17 | N/A | 9.8 CRITICAL |
| Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php. | |||||
| CVE-2024-35371 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions. | |||||
| CVE-2024-35369 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 5.5 MEDIUM |
| In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process. | |||||
| CVE-2024-35368 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 9.8 CRITICAL |
| FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c. | |||||
| CVE-2024-35367 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 9.1 CRITICAL |
| FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer | |||||
| CVE-2024-35366 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 9.1 CRITICAL |
| FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking. | |||||
