Total
396876 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-33470 | 2026-06-17 | N/A | 4.9 MEDIUM | ||
| An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2024-33469 | 2026-06-17 | N/A | 7.9 HIGH | ||
| An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java. | |||||
| CVE-2024-33465 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross Site Scripting vulnerability in MajorDoMo before v.0662e5e allows an attacker to escalate privileges via the the thumb/thumb.php component. | |||||
| CVE-2024-33454 | 1 Espressif | 1 Esp-idf | 2026-06-17 | N/A | 6.5 MEDIUM |
| Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component. | |||||
| CVE-2024-33453 | 1 Espressif | 1 Esp-idf | 2026-06-17 | N/A | 8.1 HIGH |
| Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component. | |||||
| CVE-2024-33452 | 1 Openresty | 1 Lua-nginx-module | 2026-06-17 | N/A | 7.7 HIGH |
| An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request. | |||||
| CVE-2024-33450 | 2026-06-17 | N/A | 7.5 HIGH | ||
| SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information | |||||
| CVE-2024-33449 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary code via a POST request in the url parameter | |||||
| CVE-2024-33445 | 1 Hisiphp | 1 Hisiphp | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component. | |||||
| CVE-2024-33444 | 1 Onethink | 1 Onethink | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component. | |||||
| CVE-2024-33443 | 1 Onethink | 1 Onethink | 2026-06-17 | N/A | 7.1 HIGH |
| An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component. | |||||
| CVE-2024-33442 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 4.3 MEDIUM |
| An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component. | |||||
| CVE-2024-33439 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters. | |||||
| CVE-2024-33438 | 1 Cubecart | 1 Cubecart | 2026-06-17 | N/A | 8.0 HIGH |
| File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. | |||||
| CVE-2024-33437 | 1 Mikegualtieri | 1 Css Exfil Protection | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style Rules. | |||||
| CVE-2024-33436 | 1 Mikegualtieri | 1 Css Exfil Protection | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables | |||||
| CVE-2024-33435 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.php backend function | |||||
| CVE-2024-33434 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering. | |||||
| CVE-2024-33433 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page. | |||||
| CVE-2024-33431 | 1 Stsaz | 1 Phiola | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file. | |||||
