Vulnerabilities (CVE)

Filtered by CWE-94
Total 6562 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30964 2026-06-17 N/A 7.8 HIGH
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator
CVE-2024-30963 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script.
CVE-2024-30962 1 Openrobotics 1 Robot Operating System 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process
CVE-2024-30961 1 Openrobotics 1 Robot Operating System 2026-06-17 N/A 7.8 HIGH
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.
CVE-2024-30923 1 Derbynet 1 Derbynet 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering
CVE-2024-30878 1 Rageframe 1 Rageframe 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the upload_drive parameter.
CVE-2024-30868 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.
CVE-2024-30858 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2026-06-17 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.
CVE-2024-30845 1 Rainbow External Link Network Disk Project 1 Rainbow External Link Network Disk 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation component of the input parameters.
CVE-2024-30568 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVE-2024-30567 2026-06-17 N/A 6.3 MEDIUM
An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality.
CVE-2024-30565 1 Seacms 1 Seacms 2026-06-17 N/A 8.8 HIGH
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.
CVE-2024-30202 1 Gnu 2 Emacs, Org Mode 2026-06-17 N/A 7.8 HIGH
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
CVE-2024-2610 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 6.1 MEDIUM
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2497 1 Raspap 1 Raspap 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-2209 1 Hp 56 26k67a, 26k67a Firmware, 26k67b and 53 more 2026-06-17 N/A 6.3 MEDIUM
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.
CVE-2024-2195 1 Aimstack 1 Aim 2026-06-17 N/A 9.8 CRITICAL
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py` file, where improper restriction of user access to the `RunView` object allows for the execution of arbitrary code via the `query` parameter. This issue enables attackers to execute arbitrary commands on the server, potentially leading to full system compromise.
CVE-2024-2097 2026-06-17 N/A 7.5 HIGH
An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.
CVE-2024-29991 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 5.0 MEDIUM
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2024-29937 2 Freebsd, Openbsd 2 Freebsd, Openbsd 2026-06-17 N/A 9.8 CRITICAL
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.