Total
398401 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25817 | 1 Eza.rock | 1 Eza | 2026-06-17 | N/A | 7.8 HIGH |
| Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components. | |||||
| CVE-2024-25814 | 1 Airc | 1 Mynet | 2026-06-17 | N/A | 6.1 MEDIUM |
| MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter. | |||||
| CVE-2024-25812 | 1 Airc | 1 Mynet | 2026-06-17 | N/A | 6.1 MEDIUM |
| MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter. | |||||
| CVE-2024-25811 | 1 Iteachyou | 1 Dreamer Cms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information. | |||||
| CVE-2024-25808 | 1 Lycheeorg | 1 Lychee | 2026-06-17 | N/A | 8.3 HIGH |
| Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function. | |||||
| CVE-2024-25807 | 1 Lycheeorg | 1 Lychee | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album. | |||||
| CVE-2024-25802 | 1 Skinsoft | 1 S-museum | 2026-06-17 | N/A | 9.8 CRITICAL |
| SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content. | |||||
| CVE-2024-25801 | 1 Skinsoft | 1 S-museum | 2026-06-17 | N/A | 6.1 MEDIUM |
| SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) of a file. | |||||
| CVE-2024-25770 | 1 Libming | 1 Libming | 2026-06-17 | N/A | 4.3 MEDIUM |
| libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. | |||||
| CVE-2024-25768 | 1 Trusteddomain | 1 Opendmarc | 2026-06-17 | N/A | 7.5 HIGH |
| OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c. | |||||
| CVE-2024-25767 | 1 Emqx | 1 Nanomq | 2026-06-17 | N/A | 6.5 MEDIUM |
| nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c. | |||||
| CVE-2024-25763 | 1 Opennds | 1 Opennds | 2026-06-17 | N/A | 5.5 MEDIUM |
| openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c. | |||||
| CVE-2024-25756 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function. | |||||
| CVE-2024-25753 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formSetDeviceName function. | |||||
| CVE-2024-25751 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function. | |||||
| CVE-2024-25748 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetIpMacBind function. | |||||
| CVE-2024-25746 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function. | |||||
| CVE-2024-25744 | 1 Linux | 1 Linux Kernel | 2026-06-17 | N/A | 8.8 HIGH |
| In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c. | |||||
| CVE-2024-25743 | 2026-06-17 | N/A | 7.1 HIGH | ||
| In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES. | |||||
| CVE-2024-25742 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES. | |||||
