Vulnerabilities (CVE)

Total 395801 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42736 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 7.8 HIGH
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
CVE-2024-42733 1 Docmosis 1 Tornado 2026-06-17 N/A 9.8 CRITICAL
An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path input
CVE-2024-42718 1 Croogo 1 Croogo 2026-06-17 N/A 6.5 MEDIUM
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.
CVE-2024-42699 1 Alkacon 1 Opencms 2026-06-17 N/A 6.5 MEDIUM
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field
CVE-2024-42698 1 Shedaniel 1 Roughlyenoughitems 2026-06-17 N/A 4.3 MEDIUM
Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to validate slot index and decrement stack count in the Roughly Enough Items (REI) mod for Minecraft, which allows in-game item duplication.
CVE-2024-42697 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.
CVE-2024-42681 1 Xuxueli 1 Xxl-job 2026-06-17 N/A 8.8 HIGH
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
CVE-2024-42680 1 Cysoft168 1 Super Easy Enterprise Management System 2026-06-17 N/A 5.5 MEDIUM
An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single quotation mark.
CVE-2024-42679 1 Cysoft168 1 Super Easy Enterprise Management System 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
CVE-2024-42678 1 Cysoft168 1 Super Easy Enterprise Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.
CVE-2024-42677 1 Isellerpal 1 Enterprise Resource Management System 2026-06-17 N/A 5.5 MEDIUM
An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component
CVE-2024-42676 1 Isellerpal 1 Enterprise Resource Management System 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component
CVE-2024-42671 2026-06-17 N/A 6.1 MEDIUM
A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities.
CVE-2024-42662 1 Apolloconfig 1 Apollo 2026-06-17 N/A 7.5 HIGH
An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVE-2024-42658 1 Nepstech 2 Ntpl-xpon1gfevn, Ntpl-xpon1gfevn Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
CVE-2024-42657 1 Nepstech 2 Ntpl-xpon1gfevn, Ntpl-xpon1gfevn Firmware 2026-06-17 N/A 7.5 HIGH
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
CVE-2024-42655 1 Emqx 1 Nanomq 2026-06-17 N/A 8.8 HIGH
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.
CVE-2024-42651 1 Emqx 1 Nanomq 2026-06-17 N/A 7.5 HIGH
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
CVE-2024-42650 1 Emqx 1 Nanomq 2026-06-17 N/A 7.5 HIGH
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
CVE-2024-42649 1 Emqx 1 Nanomq 2026-06-17 N/A 6.5 MEDIUM
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.