Vulnerabilities (CVE)

Total 395450 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-54804 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.
CVE-2024-54803 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.
CVE-2024-54802 1 Netgear 2 Wnr854t, Wnr854t Firmware 2026-06-17 N/A 9.8 CRITICAL
In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.
CVE-2024-54795 1 Eng 1 Spagobi 2026-06-17 N/A 5.4 MEDIUM
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.
CVE-2024-54794 1 Eng 1 Spagobi 2026-06-17 N/A 9.1 CRITICAL
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
CVE-2024-54792 1 Eng 1 Spagobi 2026-06-17 N/A 6.1 MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.
CVE-2024-54790 1 Phpgurukul 1 Pre-school Enrollment System 2026-06-17 N/A 7.5 HIGH
A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.
CVE-2024-54780 1 Netgate 2 Pfsense Ce, Pfsense Plus 2026-06-17 N/A 8.8 HIGH
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.
CVE-2024-54779 1 Netgate 2 Pfsense Ce, Pfsense Plus 2026-06-17 N/A 5.4 MEDIUM
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
CVE-2024-54775 1 Dcatadmin 1 Dcat Admin 2026-06-17 N/A 4.8 MEDIUM
Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /admin/auth/extensions.
CVE-2024-54774 1 Dcatadmin 1 Dcat Admin 2026-06-17 N/A 4.8 MEDIUM
Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.
CVE-2024-54772 1 Mikrotik 1 Routeros 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
CVE-2024-54767 2026-06-17 N/A 7.5 HIGH
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.
CVE-2024-54764 2026-06-17 N/A 6.5 MEDIUM
An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
CVE-2024-54763 2026-06-17 N/A 6.5 MEDIUM
An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.
CVE-2024-54762 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 6.3 MEDIUM
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.
CVE-2024-54761 1 Bigantsoft 1 Bigant Office Messenger 5 2026-06-17 N/A 6.3 MEDIUM
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
CVE-2024-54756 2026-06-17 N/A 9.8 CRITICAL
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.
CVE-2024-54751 2026-06-17 N/A 9.8 CRITICAL
COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
CVE-2024-54750 2026-06-17 N/A 9.8 CRITICAL
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In Ubiquiti's view there is no vulnerability as the Hardcoded Password should be after setup not before.