Vulnerabilities (CVE)

Total 398379 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28551 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.
CVE-2024-28550 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
CVE-2024-28547 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
CVE-2024-28545 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
CVE-2024-28537 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
CVE-2024-28535 1 Tenda 1 Ac18 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
CVE-2024-28521 1 Netentsec 2 Application Security Gateway Firmware, Ns-asg 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.
CVE-2024-28520 2026-06-17 N/A 6.5 MEDIUM
File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.
CVE-2024-28519 2026-06-17 N/A 7.8 HIGH
A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privilege escalation for low-privileged users.
CVE-2024-28515 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.
CVE-2024-28458 1 Swftools 1 Swftools 2026-06-17 N/A 7.5 HIGH
Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.
CVE-2024-28456 1 Campcodes 1 Online Marriage Registration System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.
CVE-2024-28447 1 Szlbt 2 Lbt-t300-mini1, Lbt-t300-mini1 Firmware 2026-06-17 N/A 6.5 MEDIUM
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr parameters at /apply.cgi.
CVE-2024-28446 1 Szlbt 2 Lbt-t300-mini1, Lbt-t300-mini1 Firmware 2026-06-17 N/A 5.7 MEDIUM
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_netmask parameter at /apply.cgi.
CVE-2024-28442 1 Yealink 2 Vp59, Vp59 Firmware 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.
CVE-2024-28441 1 Magicflue 1 Magicflue 2026-06-17 N/A 9.8 CRITICAL
File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint.
CVE-2024-28436 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.
CVE-2024-28435 1 Twenty 1 Twenty 2026-06-17 N/A 5.4 MEDIUM
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
CVE-2024-28434 1 Twenty 1 Twenty 2026-06-17 N/A 7.6 HIGH
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
CVE-2024-28432 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.