Vulnerabilities (CVE)

Total 398401 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25817 1 Eza.rock 1 Eza 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.
CVE-2024-25814 1 Airc 1 Mynet 2026-06-17 N/A 6.1 MEDIUM
MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.
CVE-2024-25812 1 Airc 1 Mynet 2026-06-17 N/A 6.1 MEDIUM
MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.
CVE-2024-25811 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 6.5 MEDIUM
An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
CVE-2024-25808 1 Lycheeorg 1 Lychee 2026-06-17 N/A 8.3 HIGH
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.
CVE-2024-25807 1 Lycheeorg 1 Lychee 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.
CVE-2024-25802 1 Skinsoft 1 S-museum 2026-06-17 N/A 9.8 CRITICAL
SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content.
CVE-2024-25801 1 Skinsoft 1 S-museum 2026-06-17 N/A 6.1 MEDIUM
SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) of a file.
CVE-2024-25770 1 Libming 1 Libming 2026-06-17 N/A 4.3 MEDIUM
libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.
CVE-2024-25768 1 Trusteddomain 1 Opendmarc 2026-06-17 N/A 7.5 HIGH
OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.
CVE-2024-25767 1 Emqx 1 Nanomq 2026-06-17 N/A 6.5 MEDIUM
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
CVE-2024-25763 1 Opennds 1 Opennds 2026-06-17 N/A 5.5 MEDIUM
openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
CVE-2024-25756 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 8.0 HIGH
A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function.
CVE-2024-25753 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 8.8 HIGH
Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formSetDeviceName function.
CVE-2024-25751 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 9.8 CRITICAL
A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.
CVE-2024-25748 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 8.8 HIGH
A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetIpMacBind function.
CVE-2024-25746 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 8.8 HIGH
Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function.
CVE-2024-25744 1 Linux 1 Linux Kernel 2026-06-17 N/A 8.8 HIGH
In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.
CVE-2024-25743 2026-06-17 N/A 7.1 HIGH
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.
CVE-2024-25742 2026-06-17 N/A 6.5 MEDIUM
In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.