Total
395554 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-57223 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. | |||||
| CVE-2024-57222 | 1 Linksys | 2 E7350, E7350 Firmware | 2026-06-17 | N/A | 6.3 MEDIUM |
| Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function. | |||||
| CVE-2024-57214 | 1 Totolink | 2 A6000r, A6000r Firmware | 2026-06-17 | N/A | 6.3 MEDIUM |
| TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function. | |||||
| CVE-2024-57213 | 1 Totolink | 2 A6000r, A6000r Firmware | 2026-06-17 | N/A | 6.3 MEDIUM |
| TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function. | |||||
| CVE-2024-57212 | 1 Totolink | 2 A6000r, A6000r Firmware | 2026-06-17 | N/A | 5.1 MEDIUM |
| TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function. | |||||
| CVE-2024-57211 | 1 Totolink | 2 A6000r, A6000r Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function. | |||||
| CVE-2024-57190 | 1 Erxes | 1 Erxes | 2026-06-17 | N/A | 9.8 CRITICAL |
| Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint. | |||||
| CVE-2024-57189 | 1 Erxes | 1 Erxes | 2026-06-17 | N/A | 5.4 MEDIUM |
| In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler. | |||||
| CVE-2024-57186 | 1 Erxes | 1 Erxes | 2026-06-17 | N/A | 5.4 MEDIUM |
| In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler. | |||||
| CVE-2024-57184 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file. | |||||
| CVE-2024-57178 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or manipulate the software behavior. | |||||
| CVE-2024-57177 | 2026-06-17 | N/A | 7.3 HIGH | ||
| A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information | |||||
| CVE-2024-57176 | 1 Antabot | 1 White-jotter | 2026-06-17 | N/A | 7.6 HIGH |
| An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal and access sensitive endpoints via a crafted URL. | |||||
| CVE-2024-57175 | 1 Phpgurukul | 1 Online Birth Certificate System | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php. | |||||
| CVE-2024-57174 | 2026-06-17 | N/A | 8.1 HIGH | ||
| A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and point its wildcard DNS entry to an attacker-controlled IP address, making it possible to access sensitive information. | |||||
| CVE-2024-57170 | 1 Soplanning | 1 Soplanning | 2026-06-17 | N/A | 6.5 MEDIUM |
| SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality. | |||||
| CVE-2024-57169 | 1 Soplanning | 1 Soplanning | 2026-06-17 | N/A | 9.8 CRITICAL |
| A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files. | |||||
| CVE-2024-57162 | 1 Campcodes | 1 Cybercafe Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php. | |||||
| CVE-2024-57161 | 1 07fly | 1 Customer Relationship Management | 2026-06-17 | N/A | 4.3 MEDIUM |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html | |||||
| CVE-2024-57160 | 1 07fly | 1 Customer Relationship Management | 2026-06-17 | N/A | 4.3 MEDIUM |
| 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html. | |||||
