Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25392 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 5.9 MEDIUM |
| An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2. | |||||
| CVE-2024-25391 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 8.4 HIGH |
| A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2. | |||||
| CVE-2024-25390 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 8.4 HIGH |
| A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2. | |||||
| CVE-2024-25389 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 7.5 HIGH |
| RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in calc_random in drivers/misc/rt_random.c. | |||||
| CVE-2024-25388 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 8.4 HIGH |
| drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow. | |||||
| CVE-2024-25386 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Directory Traversal vulnerability in DICOMĀ® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file. | |||||
| CVE-2024-25385 | 1 Flvmeta | 1 Flvmeta | 2026-06-17 | N/A | 6.2 MEDIUM |
| An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close. | |||||
| CVE-2024-25381 | 1 Emlog | 1 Emlog | 2026-06-17 | N/A | 6.1 MEDIUM |
| There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content. | |||||
| CVE-2024-25376 | 1 Thesycon | 1 Tusbaudio | 2026-06-17 | N/A | 7.8 HIGH |
| An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode. | |||||
| CVE-2024-25373 | 1 Tenda | 2 Ac10, Ac10 Firmware | 2026-06-17 | N/A | 4.6 MEDIUM |
| Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function. | |||||
| CVE-2024-25371 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW signals vs HW exceptions. | |||||
| CVE-2024-25369 | 1 Thedaylightstudio | 1 Fuel Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter. | |||||
| CVE-2024-25366 | 1 Mz-automation | 1 Libiec61850 | 2026-06-17 | N/A | 6.2 MEDIUM |
| Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component. | |||||
| CVE-2024-25360 | 1 Motorola | 2 Cx2l, Cx2l Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip. | |||||
| CVE-2024-25359 | 1 Zuoxingdong | 1 Lagom | 2026-06-17 | N/A | 6.6 MEDIUM |
| An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file. | |||||
| CVE-2024-25355 | 2026-06-17 | N/A | 7.5 HIGH | ||
| s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component. | |||||
| CVE-2024-25354 | 2026-06-17 | N/A | 7.5 HIGH | ||
| RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function. | |||||
| CVE-2024-25351 | 1 Phpgurukul | 1 Zoo Management System | 2026-06-17 | N/A | 3.8 LOW |
| SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter. | |||||
| CVE-2024-25350 | 1 Phpgurukul | 1 Zoo Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters. | |||||
| CVE-2024-25344 | 1 Itflow | 1 Itflow | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components. | |||||
