Vulnerabilities (CVE)

Total 396904 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-32287 1 Tenda 2 W30e, W30e Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.
CVE-2024-32286 1 Tenda 2 W30e, W30e Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
CVE-2024-32285 1 Tenda 2 W30e, W30e Firmware 2026-06-17 N/A 8.0 HIGH
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.
CVE-2024-32283 1 Tenda 2 Fh1203, Fh1203 Firmware 2026-06-17 N/A 7.3 HIGH
Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
CVE-2024-32282 1 Tenda 2 Fh1202, Fh1202 Firmware 2026-06-17 N/A 6.3 MEDIUM
Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
CVE-2024-32281 1 Tenda 2 Ac7, Ac7 Firmware 2026-06-17 N/A 8.8 HIGH
Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
CVE-2024-32269 2026-06-17 N/A 7.5 HIGH
An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.
CVE-2024-32268 2026-06-17 N/A 3.3 LOW
An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.
CVE-2024-32258 2026-06-17 N/A 8.8 HIGH
The network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without authentication by fake ROM.
CVE-2024-32256 1 Phpgurukul 1 Tourism Management System 2026-06-17 N/A 8.1 HIGH
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.
CVE-2024-32254 1 Phpgurukul 1 Tourism Management System 2026-06-17 N/A 8.8 HIGH
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.
CVE-2024-32238 2026-06-17 N/A 9.8 CRITICAL
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.
CVE-2024-32236 1 Cmseasy 1 Cmseasy 2026-06-17 N/A 3.5 LOW
An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.
CVE-2024-32231 1 Stashapp 1 Stash 2026-06-17 N/A 6.3 MEDIUM
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
CVE-2024-32230 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 7.8 HIGH
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0
CVE-2024-32229 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 8.4 HIGH
FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.
CVE-2024-32228 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.6 MEDIUM
FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
CVE-2024-32213 1 Logint 1 Lomag Warehouse Management 2026-06-17 N/A 5.3 MEDIUM
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.
CVE-2024-32212 1 Logint 1 Lomag Warehouse Management 2026-06-17 N/A 8.1 HIGH
SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.
CVE-2024-32211 1 Logint 1 Lomag Warehouse Management 2026-06-17 N/A 5.5 MEDIUM
An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.