Vulnerabilities (CVE)

Total 302488 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41987 1 Apple 1 Macos 2025-06-17 N/A 5.5 MEDIUM
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.
CVE-2023-41619 1 Emlog 1 Emlog 2025-06-17 N/A 6.1 MEDIUM
Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.
CVE-2023-41603 1 Dlink 2 R15, R15 Firmware 2025-06-17 N/A 5.3 MEDIUM
D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.
CVE-2023-41069 1 Apple 2 Ipados, Iphone Os 2025-06-17 N/A 5.5 MEDIUM
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
CVE-2023-40830 1 Tenda 2 Ac6, Ac6 Firmware 2025-06-17 N/A 9.8 CRITICAL
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
CVE-2023-33760 1 Splicecom 1 Maximiser Soft Pbx 2025-06-17 N/A 5.3 MEDIUM
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
CVE-2023-33295 1 Cohesity 1 Cohesity Dataplatform 2025-06-17 N/A 6.5 MEDIUM
Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
CVE-2024-33121 1 Roothub 1 Roothub 2025-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
CVE-2024-46540 1 Emlog 1 Emlog 2025-06-17 N/A 6.3 MEDIUM
A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions to upload webshells to the target server, thereby obtaining system privileges.
CVE-2024-47913 1 Mediawiki 1 Mediawiki 2025-06-17 N/A 5.3 MEDIUM
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.
CVE-2024-44068 1 Samsung 12 Exynos 850, Exynos 850 Firmware, Exynos 980 and 9 more 2025-06-17 N/A 8.1 HIGH
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.
CVE-2025-43200 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2025-06-17 N/A 4.8 MEDIUM
This issue was addressed with improved checks. This issue is fixed in watchOS 11.3.1, macOS Ventura 13.7.4, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iPadOS 17.7.5, visionOS 2.3.1, macOS Sequoia 15.3.1, iOS 18.3.1 and iPadOS 18.3.1, macOS Sonoma 14.7.4. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CVE-2024-46292 1 Trustwave 1 Modsecurity 2025-06-17 N/A 7.5 HIGH
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).
CVE-2024-45184 1 Samsung 36 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 33 more 2025-06-17 N/A 6.2 MEDIUM
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer overflow can lead to a Denial of Service.
CVE-2024-48700 1 Kliqqi 1 Kliqqi Cms 2025-06-17 N/A 7.2 HIGH
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
CVE-2024-48112 1 Thinkphp 1 Thinkphp 2025-06-17 N/A 9.8 CRITICAL
A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
CVE-2024-34402 2 Fedoraproject, Uriparser Project 2 Fedora, Uriparser 2025-06-17 N/A 8.6 HIGH
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
CVE-2024-34403 2 Fedoraproject, Uriparser Project 2 Fedora, Uriparser 2025-06-17 N/A 5.9 MEDIUM
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
CVE-2024-23686 1 Owasp 1 Dependency-check 2025-06-17 N/A 5.3 MEDIUM
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
CVE-2024-23055 1 Plone 1 Plone Docker Official Image 2025-06-17 N/A 6.1 MEDIUM
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.