Vulnerabilities (CVE)

Total 396541 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35339 1 Tenda 2 Fh1206, Fh1206 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
CVE-2024-35338 1 Tendacn 2 I29, I29 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
CVE-2024-35333 2026-06-17 N/A 8.4 HIGH
A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially crafted input to the vulnerable function, causing a buffer overflow and potentially leading to arbitrary code execution, denial of service, or data corruption.
CVE-2024-35324 1 Douchat 1 Douchat 2026-06-17 N/A 9.8 CRITICAL
Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
CVE-2024-35322 1 Airc 1 Mynet 2026-06-17 N/A 6.1 MEDIUM
MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro parameter.
CVE-2024-35321 1 Airc 1 Mynet 2026-06-17 N/A 4.3 MEDIUM
MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter.
CVE-2024-35315 1 Mitel 2 Micollab, Mivoice Business Solution Virtual Instance 2026-06-17 N/A 5.6 MEDIUM
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary code with elevated privileges.
CVE-2024-35314 1 Mitel 2 Micollab, Mivoice Business Solution Virtual Instance 2026-06-17 N/A 9.8 CRITICAL
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts.
CVE-2024-35313 2026-06-17 N/A 7.3 HIGH
In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.
CVE-2024-35312 2026-06-17 N/A 6.2 MEDIUM
In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.
CVE-2024-35311 2026-06-17 N/A 3.3 LOW
Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access Control.
CVE-2024-35308 1 Pandorafms 1 Pandora Fms 2026-06-17 N/A 8.8 HIGH
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
CVE-2024-35307 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35306 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35305 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35304 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35303 2026-06-17 N/A 7.8 HIGH
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications contain a type confusion vulnerability while parsing specially crafted MODEL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22958)
CVE-2024-35302 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
CVE-2024-35301 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
CVE-2024-35300 1 Jetbrains 1 Teamcity 2026-06-17 N/A 3.5 LOW
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible