Vulnerabilities (CVE)

Total 395541 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57061 2026-06-17 N/A 9.8 CRITICAL
An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.
CVE-2024-57056 2026-06-17 N/A 5.4 MEDIUM
Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to impersonate an existing user session.
CVE-2024-57055 2026-06-17 N/A 5.0 MEDIUM
Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.
CVE-2024-57052 1 Youdiancms 1 Youdiancms 2026-06-17 N/A 9.8 CRITICAL
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
CVE-2024-57046 1 Netgear 2 Dgn2200, Dgn2200 Firmware 2026-06-17 N/A 8.8 HIGH
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
CVE-2024-57045 1 Dlink 2 Dir-859 A3, Dir-859 A3 Firmware 2026-06-17 N/A 9.8 CRITICAL
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
CVE-2024-57040 1 Tp-link 2 Tl-wr845n, Tl-wr845n Firmware 2026-06-17 N/A 9.8 CRITICAL
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the router. NOTE: The supplier has stated that this issue was fixed in firmware versions 250401 or later.
CVE-2024-57036 1 Totolink 2 A810r, A810r Firmware 2026-06-17 N/A 8.1 HIGH
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
CVE-2024-57035 1 Wegia 1 Wegia 2026-06-17 N/A 9.8 CRITICAL
WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
CVE-2024-57034 1 Wegia 1 Wegia 2026-06-17 N/A 9.8 CRITICAL
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
CVE-2024-57033 1 Wegia 1 Wegia 2026-06-17 N/A 6.1 MEDIUM
WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
CVE-2024-57032 1 Wegia 1 Wegia 2026-06-17 N/A 9.8 CRITICAL
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.
CVE-2024-57031 1 Wegia 1 Wegia 2026-06-17 N/A 9.8 CRITICAL
WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.
CVE-2024-57030 1 Wegia 1 Wegia 2026-06-17 N/A 8.1 HIGH
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-57026 1 Tawk 1 Tawk.to 2026-06-17 N/A 6.1 MEDIUM
TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.
CVE-2024-57025 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.8 MEDIUM
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
CVE-2024-57024 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.8 MEDIUM
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
CVE-2024-57023 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.8 MEDIUM
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
CVE-2024-57022 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg.
CVE-2024-57021 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.