Vulnerabilities (CVE)

Total 396876 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33470 2026-06-17 N/A 4.9 MEDIUM
An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-33469 2026-06-17 N/A 7.9 HIGH
An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.
CVE-2024-33465 2026-06-17 N/A 7.1 HIGH
Cross Site Scripting vulnerability in MajorDoMo before v.0662e5e allows an attacker to escalate privileges via the the thumb/thumb.php component.
CVE-2024-33454 1 Espressif 1 Esp-idf 2026-06-17 N/A 6.5 MEDIUM
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.
CVE-2024-33453 1 Espressif 1 Esp-idf 2026-06-17 N/A 8.1 HIGH
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component.
CVE-2024-33452 1 Openresty 1 Lua-nginx-module 2026-06-17 N/A 7.7 HIGH
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
CVE-2024-33450 2026-06-17 N/A 7.5 HIGH
SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information
CVE-2024-33449 2026-06-17 N/A 9.8 CRITICAL
An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary code via a POST request in the url parameter
CVE-2024-33445 1 Hisiphp 1 Hisiphp 2026-06-17 N/A 9.8 CRITICAL
An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.
CVE-2024-33444 1 Onethink 1 Onethink 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.
CVE-2024-33443 1 Onethink 1 Onethink 2026-06-17 N/A 7.1 HIGH
An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.
CVE-2024-33442 1 Flusity 1 Flusity 2026-06-17 N/A 4.3 MEDIUM
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.
CVE-2024-33439 2026-06-17 N/A 9.1 CRITICAL
An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.
CVE-2024-33438 1 Cubecart 1 Cubecart 2026-06-17 N/A 8.0 HIGH
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
CVE-2024-33437 1 Mikegualtieri 1 Css Exfil Protection 2026-06-17 N/A 7.5 HIGH
An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style Rules.
CVE-2024-33436 1 Mikegualtieri 1 Css Exfil Protection 2026-06-17 N/A 5.3 MEDIUM
An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables
CVE-2024-33435 2026-06-17 N/A 9.8 CRITICAL
Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary code via the /manage/IPSetup.php backend function
CVE-2024-33434 2026-06-17 N/A 9.8 CRITICAL
An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.
CVE-2024-33433 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
CVE-2024-33431 1 Stsaz 1 Phiola 2026-06-17 N/A 6.5 MEDIUM
An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.