Vulnerabilities (CVE)

Total 395684 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45260 1 Gl-inet 42 A1300, A1300 Firmware, Ar300m and 39 more 2026-06-17 N/A 8.0 HIGH
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.
CVE-2024-45259 1 Gl-inet 42 A1300, A1300 Firmware, Ar300m and 39 more 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.
CVE-2024-45258 2026-06-17 N/A 9.8 CRITICAL
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.
CVE-2024-45257 2026-06-17 N/A 7.3 HIGH
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.
CVE-2024-45256 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.
CVE-2024-45254 2026-06-17 N/A 7.5 HIGH
VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-45253 2026-06-17 N/A 7.5 HIGH
Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-45252 2026-06-17 N/A 9.8 CRITICAL
Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-45251 2026-06-17 N/A 9.8 CRITICAL
Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-45250 2026-06-17 N/A 4.3 MEDIUM
ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-45249 1 Peak-14 1 Cavok 2026-06-17 N/A 9.8 CRITICAL
Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-45248 2026-06-17 N/A 7.5 HIGH
Multi-DNC – CWE-35: Path Traversal: '.../...//'
CVE-2024-45247 2026-06-17 N/A 6.1 MEDIUM
Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-45246 2026-06-17 N/A 7.3 HIGH
Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element
CVE-2024-45245 2026-06-17 N/A 7.8 HIGH
Diebold Nixdorf – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-45244 1 Hyperledger 1 Fabric 2026-06-17 N/A 5.3 MEDIUM
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
CVE-2024-45242 2026-06-17 N/A 7.8 HIGH
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with the default credentials of admin/admin. An unauthorized attacker in proximity to the Wi-Fi network can exploit this window of time to execute arbitrary OS commands with root-level permissions.
CVE-2024-45241 2026-06-17 N/A 7.5 HIGH
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
CVE-2024-45240 2026-06-17 N/A 7.4 HIGH
The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On Android 12 and later, this is only exploitable by third-party applications.)
CVE-2024-45239 1 Nicmx 1 Fort-validator 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.