Vulnerabilities (CVE)

Total 395554 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57223 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
CVE-2024-57222 1 Linksys 2 E7350, E7350 Firmware 2026-06-17 N/A 6.3 MEDIUM
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
CVE-2024-57214 1 Totolink 2 A6000r, A6000r Firmware 2026-06-17 N/A 6.3 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
CVE-2024-57213 1 Totolink 2 A6000r, A6000r Firmware 2026-06-17 N/A 6.3 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.
CVE-2024-57212 1 Totolink 2 A6000r, A6000r Firmware 2026-06-17 N/A 5.1 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.
CVE-2024-57211 1 Totolink 2 A6000r, A6000r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.
CVE-2024-57190 1 Erxes 1 Erxes 2026-06-17 N/A 9.8 CRITICAL
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
CVE-2024-57189 1 Erxes 1 Erxes 2026-06-17 N/A 5.4 MEDIUM
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.
CVE-2024-57186 1 Erxes 1 Erxes 2026-06-17 N/A 5.4 MEDIUM
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.
CVE-2024-57184 1 Gpac 1 Gpac 2026-06-17 N/A 5.5 MEDIUM
An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file.
CVE-2024-57178 2026-06-17 N/A 5.9 MEDIUM
An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or manipulate the software behavior.
CVE-2024-57177 2026-06-17 N/A 7.3 HIGH
A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information
CVE-2024-57176 1 Antabot 1 White-jotter 2026-06-17 N/A 7.6 HIGH
An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal and access sensitive endpoints via a crafted URL.
CVE-2024-57175 1 Phpgurukul 1 Online Birth Certificate System 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.
CVE-2024-57174 2026-06-17 N/A 8.1 HIGH
A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and point its wildcard DNS entry to an attacker-controlled IP address, making it possible to access sensitive information.
CVE-2024-57170 1 Soplanning 1 Soplanning 2026-06-17 N/A 6.5 MEDIUM
SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality.
CVE-2024-57169 1 Soplanning 1 Soplanning 2026-06-17 N/A 9.8 CRITICAL
A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.
CVE-2024-57162 1 Campcodes 1 Cybercafe Management System 2026-06-17 N/A 7.2 HIGH
Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.
CVE-2024-57161 1 07fly 1 Customer Relationship Management 2026-06-17 N/A 4.3 MEDIUM
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
CVE-2024-57160 1 07fly 1 Customer Relationship Management 2026-06-17 N/A 4.3 MEDIUM
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.