Vulnerabilities (CVE)

Total 396887 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33124 1 Roothub 1 Roothub 2026-06-17 N/A 9.8 CRITICAL
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
CVE-2024-33122 1 Roothub 1 Roothub 2026-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
CVE-2024-33121 1 Roothub 1 Roothub 2026-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
CVE-2024-33118 1 Luckyframe 1 Luckyframeweb 2026-06-17 N/A 7.5 HIGH
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.
CVE-2024-33117 1 Crmeb 1 Crmeb Java 2026-06-17 N/A 5.3 MEDIUM
crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.
CVE-2024-33113 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 5.3 MEDIUM
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
CVE-2024-33112 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
CVE-2024-33111 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 5.4 MEDIUM
D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.
CVE-2024-33110 1 Dlink 2 Dir-845l, Dir-845l Firmware 2026-06-17 N/A 9.1 CRITICAL
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
CVE-2024-33103 2026-06-17 N/A 6.1 MEDIUM
An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product.
CVE-2024-33102 1 Thinksaas 1 Thinksaas 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.
CVE-2024-33101 1 Thinksaas 1 Thinksaas 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the word parameter.
CVE-2024-33078 1 Tencent 1 Libpag 2026-06-17 N/A 9.8 CRITICAL
Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.
CVE-2024-33073 1 Qualcomm 318 Ar8035, Ar8035 Firmware, Csr8811 and 315 more 2026-06-17 N/A 8.2 HIGH
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33071 1 Qualcomm 10 Mdm9628, Mdm9628 Firmware, Qca6564a and 7 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
CVE-2024-33070 1 Qualcomm 10 Mdm9628, Mdm9628 Firmware, Qca6564a and 7 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33069 1 Qualcomm 88 Fastconnect 6800, Fastconnect 6800 Firmware, Fastconnect 6900 and 85 more 2026-06-17 N/A 7.5 HIGH
Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.
CVE-2024-33068 1 Qualcomm 244 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 241 more 2026-06-17 N/A 7.5 HIGH
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-33067 1 Qualcomm 154 Ar8035, Ar8035 Firmware, C-v2x 9150 and 151 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
CVE-2024-33066 1 Qualcomm 142 Csr8811, Csr8811 Firmware, Immersive Home 214 Platform and 139 more 2026-06-17 N/A 9.8 CRITICAL
Memory corruption while redirecting log file to any file location with any file name.