Total
395684 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-45260 | 1 Gl-inet | 42 A1300, A1300 Firmware, Ar300m and 39 more | 2026-06-17 | N/A | 8.0 HIGH |
| An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it. | |||||
| CVE-2024-45259 | 1 Gl-inet | 42 A1300, A1300 Firmware, Ar300m and 39 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted. | |||||
| CVE-2024-45258 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design. | |||||
| CVE-2024-45257 | 2026-06-17 | N/A | 7.3 HIGH | ||
| A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py. | |||||
| CVE-2024-45256 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py. | |||||
| CVE-2024-45254 | 2026-06-17 | N/A | 7.5 HIGH | ||
| VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-45253 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |||||
| CVE-2024-45252 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |||||
| CVE-2024-45251 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |||||
| CVE-2024-45250 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-45249 | 1 Peak-14 | 1 Cavok | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |||||
| CVE-2024-45248 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Multi-DNC – CWE-35: Path Traversal: '.../...//' | |||||
| CVE-2024-45247 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | |||||
| CVE-2024-45246 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element | |||||
| CVE-2024-45245 | 2026-06-17 | N/A | 7.8 HIGH | ||
| Diebold Nixdorf – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-45244 | 1 Hyperledger | 1 Fabric | 2026-06-17 | N/A | 5.3 MEDIUM |
| Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window. | |||||
| CVE-2024-45242 | 2026-06-17 | N/A | 7.8 HIGH | ||
| EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentials of admin/admin. An unauthorized attacker in proximity to the Wi-Fi network can exploit this window of time to execute arbitrary OS commands with root-level permissions. | |||||
| CVE-2024-45241 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information. | |||||
| CVE-2024-45240 | 2026-06-17 | N/A | 7.4 HIGH | ||
| The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On Android 12 and later, this is only exploitable by third-party applications.) | |||||
| CVE-2024-45239 | 1 Nicmx | 1 Fort-validator | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing. | |||||
