Vulnerabilities (CVE)

Total 395559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57549 1 Cmsimple 1 Cmsimple 2026-06-17 N/A 7.5 HIGH
CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
CVE-2024-57548 1 Cmsimple 1 Cmsimple 2026-06-17 N/A 9.1 CRITICAL
CMSimple 5.16 allows the user to edit log.php file via print page.
CVE-2024-57547 1 Cmsimple 1 Cmsimple 2026-06-17 N/A 7.5 HIGH
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.
CVE-2024-57546 1 Cmsimple 1 Cmsimple 2026-06-17 N/A 7.5 HIGH
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.
CVE-2024-57545 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 5.5 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.
CVE-2024-57544 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 5.5 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.
CVE-2024-57543 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 5.5 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.
CVE-2024-57542 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 8.8 HIGH
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.
CVE-2024-57541 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 5.5 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.
CVE-2024-57540 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 6.5 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.
CVE-2024-57539 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 8.2 HIGH
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
CVE-2024-57538 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 6.5 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification.
CVE-2024-57537 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 6.3 MEDIUM
Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.
CVE-2024-57536 1 Linksys 2 E8450, E8450 Firmware 2026-06-17 N/A 8.0 HIGH
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
CVE-2024-57522 1 Oretnom23 1 Packers And Movers Management System 2026-06-17 N/A 6.4 MEDIUM
SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.
CVE-2024-57521 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 10.0 CRITICAL
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
CVE-2024-57520 1 Sangoma 1 Asterisk 2026-06-17 N/A 9.8 CRITICAL
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.
CVE-2024-57519 1 Open5gs 1 Open5gs 2026-06-17 N/A 7.5 HIGH
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
CVE-2024-57514 2026-06-17 N/A 4.8 MEDIUM
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.
CVE-2024-57513 2026-06-17 N/A 6.5 MEDIUM
A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.