23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 22351-22400 of 23871 CVEs Page 448 of 478
CVE-2024-57154
Analyzed
9.8
Unknown

Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

2025-08-21
CVE-2024-57152
Analyzed
7.5
Unknown

Incorrect access control in the preHandle function of my-site v1

2025-08-21
CVE-2024-56836
Analyzed
7.5
Siemens RUGGEDCOM ROX MX5000

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2

2025-12-11
CVE-2024-56835
Analyzed
8.8
Siemens RUGGEDCOM ROX MX5000

A vulnerability has been identified in RUGGEDCOM ROX II family (All versions < V2

2025-12-10
CVE-2024-56808
Analyzed
7.8
QNAP Systems Media Streaming add-on

A command injection vulnerability has been reported to affect Media Streaming add-on

2026-02-13
CVE-2024-56373
Analyzed
8.4
Apache Apache Airflow

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server...

2026-02-25
CVE-2024-56190
Analyzed
7.8
Google Android

In wl_update_hidden_ap_ie() of wl_cfgscan

2025-09-04
CVE-2024-56189
Analyzed
7.5
Google Android

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec

2025-09-04
CVE-2024-56179
Analyzed
7.8
Unknown

In MindManager Windows versions prior to 24

2025-08-23
CVE-2024-56143
Analyzed
8.2
strapi strapi

Strapi is an open-source headless content management system

2025-10-16
CVE-2024-56089
Analyzed
7.5
Unknown

An issue in Technitium through v13

2025-12-02
CVE-2024-55568
Analyzed
7.5
Modem

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 240...

2025-10-20
CVE-2024-55270
Analyzed
8.8
Unknown

phpgurukul Student Management System 1

2026-02-18
CVE-2024-55027
Analyzed
7.5
Weintek

Weintek cMT-3072XH2 easyweb v2

2026-03-05
CVE-2024-55024
Analyzed
8.8
Unknown

An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2

2026-03-04
CVE-2024-55022
Analyzed
8.8
Weintek

Weintek cMT-3072XH2 easyweb v2

2026-03-05
CVE-2024-55021
Analyzed
7.5
Weintek

Weintek cMT-3072XH2 easyweb v2

2026-03-05
CVE-2024-55020
Analyzed
9.8
Unknown cMT-3072XH2 (easyweb)

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 allows attackers to execute arbitrary commands with root privi...

2026-03-04
CVE-2024-55019
Analyzed
7.5
Unknown

Incorrect access control in the component download_wb

2026-03-05
CVE-2024-55017
Analyzed
7.5
Account

Account Takeover in Corezoid 6

2025-09-30
CVE-2024-54678
Analyzed
8.2
Siemens SIMATIC PCS neo V4.1

A vulnerability has been identified in SIMATIC PCS neo V4

2025-08-12
CVE-2024-54263
Analyzed
7.5
Talemy Spirit Framework

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allow...

2026-02-02
CVE-2024-54085
KEV Analyzed
9.5
AMI MegaRAC-SPx

AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.

2025-07-10
CVE-2024-53946
Analyzed
8.8
Unknown

The KuWFi 4G LTE AC900 router 1

2025-08-14
CVE-2024-53945
Analyzed
8.8
Unknown

The KuWFi 4G AC900 LTE router 1

2025-08-14
CVE-2024-5386
Analyzed
9.6
lunary-ai lunary-ai/lunary

In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can explo...

2026-02-02
CVE-2024-53735
Analyzed
7.1
corourke iPhone Webclip Manager

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Corourke iPhone Webclip Manager allows Stored XS...

2026-01-06
CVE-2024-53684
Analyzed
7.5
Socomec DIRIS Digiware M-70

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1

2025-12-02
CVE-2024-53621
7.5

A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1

2025-07-06
CVE-2024-53496
Analyzed
9.8
Unknown

Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

2025-08-23
CVE-2024-53495
Analyzed
7.5
Unknown

Incorrect access control in the preHandle function of my-site v1

2025-08-21
CVE-2024-53412
Analyzed
8.4
NietThijmen

Command injection in the connect function in NietThijmen ShoppingCart 0

2026-04-16
CVE-2024-53286
Analyzed
7.2
Synology Synology Router Manager (SRM)

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Rout...

2025-07-23
CVE-2024-52786
Analyzed
9.8
Unknown

An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted UR...

2025-08-23
CVE-2024-52284
Analyzed
7.7
SUSE Rancher

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources could retrieve Helm values contai...

2025-09-02
CVE-2024-51770
Analyzed
7.5
HPE HPE AutoPass License Server

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-15
CVE-2024-51769
Analyzed
7.5
HPE HPE AutoPass License Server

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-14
CVE-2024-51768
Analyzed
8
HPE HPE AutoPass License Server

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-14
CVE-2024-51767
Analyzed
7.3
HPE HPE AutoPass License Server

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-14
CVE-2024-51348
Analyzed
8.8
Unknown

A stack-based buffer overflow vulnerability in the P2P API service in BS Producten Petcam with firmware 33

2026-03-26
CVE-2024-51346
Analyzed
7.7
Eufy

An issue in Eufy Homebase 2 version 3

2026-03-26
CVE-2024-51316
Analyzed
7.5
Tenda TX9

The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName

2026-07-27
CVE-2024-51315
Analyzed
9.8
Tenda TX9

The Tenda TX9 router firmware version V22.03.02.20 contains a stack overflow vulnerability in the /goform/SetOnlineDevName endpoint that may result in...

2026-07-27
CVE-2024-51314
Analyzed
9.8
Tenda TX9

The Tenda TX9 router firmware version V22.03.02.20 contains a stack overflow vulnerability in the /goform/setMacFilterCfg endpoint that allows for arb...

2026-07-27
CVE-2024-51313
Analyzed
9.8
Tenda TX9 router firmware

The Tenda TX9 router firmware version V22.03.02.20 contains a stack-based buffer overflow vulnerability in the /goform/SetVirtualServerCfg endpoint.

2026-07-28
CVE-2024-51312
Analyzed
9.8
Tenda TX9

A stack overflow vulnerability in the Tenda TX9 firmware allows for potential remote code execution via the /goform/SetStaticRouteCfg interface.

2026-07-27
CVE-2024-51311
Analyzed
9.8
Tenda TX9

The Tenda TX9 router firmware version V22.03.02.05 contains a stack overflow vulnerability in the SetNetControlList function, allowing unauthenticated...

2026-07-27
CVE-2024-51092
Analyzed
9.1
HP

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsC...

2026-05-09
CVE-2024-50645
Analyzed
9.8
MallChat

MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

2025-08-23
CVE-2024-50641
Analyzed
8.1
Unknown

An authentication bypass vulnerability in PandoraNext-TokensTool v0

2025-08-21