Vulnerabilities (CVE)

Total 398466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24548 1 Estore-wss 1 Payment Ex 2026-06-17 N/A 6.5 MEDIUM
Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise using Payment EX.
CVE-2024-24543 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.
CVE-2024-24539 1 Fusionpbx 1 Fusionpbx 2026-06-17 N/A 5.3 MEDIUM
FusionPBX before 5.2.0 does not validate a session.
CVE-2024-24525 1 Epoint 1 Epointwebbuilder 2026-06-17 N/A 9.8 CRITICAL
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.
CVE-2024-24524 1 Flusity 1 Flusity 2026-06-17 N/A 8.8 HIGH
Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.
CVE-2024-24512 1 Pkp.sfu 1 Open Journal Systems 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.
CVE-2024-24511 1 Pkp.sfu 1 Open Journal Systems 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.
CVE-2024-24510 1 Alinto 1 Sogo 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
CVE-2024-24507 1 Act-on 1 Act-on 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.
CVE-2024-24506 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.
CVE-2024-24496 1 Remyandrade 1 Daily Habit Tracker 2026-06-17 N/A 9.8 CRITICAL
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
CVE-2024-24495 1 Remyandrade 1 Daily Habit Tracker 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.
CVE-2024-24494 1 Remyandrade 1 Daily Habit Tracker 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.
CVE-2024-24488 1 Tendacn 2 Cp3, Cp3 Firmware 2026-06-17 N/A 5.5 MEDIUM
An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.
CVE-2024-24487 1 Silextechnology 2 Ds-600, Ds-600 Firmware 2026-06-17 N/A 6.8 MEDIUM
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command.
CVE-2024-24486 1 Silextechnology 2 Ds-600, Ds-600 Firmware 2026-06-17 N/A 9.1 CRITICAL
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.
CVE-2024-24485 1 Silextechnology 2 Ds-600, Ds-600 Firmware 2026-06-17 N/A 7.5 HIGH
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.
CVE-2024-24482 2 Apktool, Microsoft 2 Apktool, Windows 2026-06-17 N/A 9.8 CRITICAL
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
CVE-2024-24479 2 Fedoraproject, Wireshark 2 Fedora, Wireshark 2026-06-17 N/A 7.5 HIGH
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVE-2024-24478 1 Wireshark 1 Wireshark 2026-06-17 N/A 7.5 HIGH
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.