Total
395554 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57254 | 1 Denx | 1 U-boot | 2026-06-17 | N/A | 7.1 HIGH |
| An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesystem. | |||||
| CVE-2024-57252 | 1 Otcms | 1 Otcms | 2026-06-17 | N/A | 4.3 MEDIUM |
| OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily. | |||||
| CVE-2024-57249 | 1 Gleamtech | 1 Filevista | 2026-06-17 | N/A | 6.5 MEDIUM |
| Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication process and grants attackers access to sensitive image files without proper login credentials. | |||||
| CVE-2024-57248 | 1 Gleamtech | 1 Filevista | 2026-06-17 | N/A | 6.3 MEDIUM |
| Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files. | |||||
| CVE-2024-57241 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 6.5 MEDIUM |
| Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection. | |||||
| CVE-2024-57240 | 1 Apryse | 1 Webviewer | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file. | |||||
| CVE-2024-57238 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter. | |||||
| CVE-2024-57237 | 2026-06-17 | N/A | 6.3 MEDIUM | ||
| Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute injected JavaScript code. | |||||
| CVE-2024-57235 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function. | |||||
| CVE-2024-57234 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function. | |||||
| CVE-2024-57233 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function. | |||||
| CVE-2024-57232 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. | |||||
| CVE-2024-57231 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function. | |||||
| CVE-2024-57230 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. | |||||
| CVE-2024-57229 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function. | |||||
| CVE-2024-57228 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function. | |||||
| CVE-2024-57227 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function. | |||||
| CVE-2024-57226 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function. | |||||
| CVE-2024-57225 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function. | |||||
| CVE-2024-57224 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. | |||||
