Vulnerabilities (CVE)

Total 395451 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-55019 1 Weintek 3 Cmt-3072xh2, Cmt-3072xh2 Firmware, Easyweb 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.
CVE-2024-55017 2026-06-17 N/A 7.5 HIGH
Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain unauthorized access to victim accounts.
CVE-2024-55016 1 Phpgurukul 1 Student Record System 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
CVE-2024-55009 1 Datax 1 Autobib 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.
CVE-2024-55000 1 Mayurik 1 House Rental Management System 2026-06-17 N/A 5.4 MEDIUM
Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.
CVE-2024-54984 2026-06-17 N/A 9.8 CRITICAL
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.
CVE-2024-54983 2026-06-17 N/A 9.8 CRITICAL
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
CVE-2024-54982 2026-06-17 N/A N/A
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message. NOTE: Quectel disputes this because the issue is in the chipset supply chain and is not localized to one or more Quectel products.
CVE-2024-54961 1 Nagios 1 Nagios Xi 2026-06-17 N/A 6.5 MEDIUM
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
CVE-2024-54960 1 Nagios 1 Nagios Xi 2026-06-17 N/A 6.5 MEDIUM
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
CVE-2024-54959 1 Nagios 1 Nagios Xi 2026-06-17 N/A 6.1 MEDIUM
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
CVE-2024-54958 1 Nagios 1 Nagios Xi 2026-06-17 N/A 6.1 MEDIUM
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
CVE-2024-54957 1 Nagios 1 Nagios Xi 2026-06-17 N/A 6.1 MEDIUM
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
CVE-2024-54954 1 Zhyd 1 Oneblog 2026-06-17 N/A 8.0 HIGH
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
CVE-2024-54952 1 Mikrotik 1 Routeros 2026-06-17 N/A 7.5 HIGH
MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.
CVE-2024-54951 1 Monicahq 1 Monica 2026-06-17 N/A 5.4 MEDIUM
Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.
CVE-2024-54938 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.5 HIGH
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.
CVE-2024-54937 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 5.3 MEDIUM
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets.
CVE-2024-54936 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.
CVE-2024-54935 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.