Vulnerabilities (CVE)

Total 396943 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30849 1 Donbermoy 1 Complete E-commerce Site 2026-06-17 N/A 9.8 CRITICAL
Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.
CVE-2024-30848 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject arbitrary web script or HTML via the version parameter.
CVE-2024-30845 1 Rainbow External Link Network Disk Project 1 Rainbow External Link Network Disk 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation component of the input parameters.
CVE-2024-30840 1 Tenda 2 Ac15, Ac15 Firmware 2026-06-17 N/A 6.5 MEDIUM
A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.
CVE-2024-30809 1 Axiosys 1 Bento4 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
CVE-2024-30808 1 Axiosys 1 Bento4 2026-06-17 N/A 2.7 LOW
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
CVE-2024-30807 1 Axiosys 1 Bento4 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
CVE-2024-30806 1 Axiosys 1 Bento4 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
CVE-2024-30804 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.
CVE-2024-30802 2026-06-17 N/A 9.8 CRITICAL
An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.
CVE-2024-30800 1 Dronecode 1 Px4 Drone Autopilot 2026-06-17 N/A 5.6 MEDIUM
PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.
CVE-2024-30799 1 Dronecode 1 Px4 Drone Autopilot 2026-06-17 N/A 4.4 MEDIUM
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.
CVE-2024-30656 1 Fireboltt 2 Dream, Dream Firmware 2026-06-17 N/A 7.5 HIGH
An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.
CVE-2024-30645 1 Tenda 2 Ac15, Ac15 Firmware 2026-06-17 N/A 8.0 HIGH
Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.
CVE-2024-30639 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.
CVE-2024-30638 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.
CVE-2024-30637 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 8.8 HIGH
Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.
CVE-2024-30636 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.
CVE-2024-30635 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.
CVE-2024-30634 1 Tenda 2 F1202, F1202 Firmware 2026-06-17 N/A 8.0 HIGH
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.