Vulnerabilities (CVE)

Total 395450 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-54880 1 Seacms 1 Seacms 2026-06-17 N/A 9.1 CRITICAL
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
CVE-2024-54853 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.
CVE-2024-54852 1 Sismics 1 Teedy 2026-06-17 N/A 9.8 CRITICAL
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
CVE-2024-54851 1 Sismics 1 Teedy 2026-06-17 N/A 8.8 HIGH
Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
CVE-2024-54849 1 Cpplusworld 2 Cp-vnr-3104, Cp-vnr-3104 Firmware 2026-06-17 N/A 5.9 MEDIUM
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.
CVE-2024-54848 1 Cpplusworld 2 Cp-vnr-3104, Cp-vnr-3104 Firmware 2026-06-17 N/A 7.4 HIGH
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.
CVE-2024-54847 1 Cpplusworld 2 Cp-vnr-3104, Cp-vnr-3104 Firmware 2026-06-17 N/A 5.9 MEDIUM
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.
CVE-2024-54846 1 Cpplusworld 2 Cp-vnr-3104, Cp-vnr-3104 Firmware 2026-06-17 N/A 5.9 MEDIUM
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.
CVE-2024-54842 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.
CVE-2024-54840 1 Cyberark 1 Privileged Access Manager 2026-06-17 N/A 4.2 MEDIUM
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
CVE-2024-54820 2026-06-17 N/A 9.8 CRITICAL
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.
CVE-2024-54819 2026-06-17 N/A 9.1 CRITICAL
I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php
CVE-2024-54818 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 8.8 HIGH
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.
CVE-2024-54811 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.
CVE-2024-54810 1 Phpgurukul 1 Pre-school Enrollment System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.
CVE-2024-54809 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.
CVE-2024-54808 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.
CVE-2024-54807 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.
CVE-2024-54806 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.
CVE-2024-54805 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.