Vulnerabilities (CVE)

Total 395945 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-41710 1 Mitel 30 6863i Sip, 6863i Sip Firmware, 6865i Sip and 27 more 2026-06-17 N/A 7.2 HIGH
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
CVE-2024-41709 1 Backdropcms 1 Backdrop 2026-06-17 N/A 4.8 MEDIUM
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
CVE-2024-41708 2026-06-17 N/A 7.5 HIGH
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.
CVE-2024-41707 1 Archerirm 1 Archer 2026-06-17 N/A 4.8 MEDIUM
An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
CVE-2024-41706 1 Archerirm 1 Archer 2026-06-17 N/A 7.3 HIGH
A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 P4 (6.14.0.4) is also a fixed release.
CVE-2024-41705 1 Archerirm 1 Archer 2026-06-17 N/A 7.1 HIGH
A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14.P4 (6.14.0.4) and 6.13 P4 (6.13.0.4) are also fixed releases. This vulnerability is similar to, but not identical to, CVE-2023-30639.
CVE-2024-41704 1 Librechat 1 Librechat 2026-06-17 N/A 9.8 CRITICAL
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.
CVE-2024-41703 1 Librechat 1 Librechat 2026-06-17 N/A 9.8 CRITICAL
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
CVE-2024-41702 1 Siberiancms 1 Siberiancms 2026-06-17 N/A 9.8 CRITICAL
SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-41701 2026-06-17 N/A 5.3 MEDIUM
AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41700 1 Barix 1 Sip Client Firmware 2026-06-17 N/A 7.5 HIGH
Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41699 1 Priority-software 1 Priority 2026-06-17 N/A 4.4 MEDIUM
Priority – CWE-552: Files or Directories Accessible to External Parties
CVE-2024-41698 1 Priority-software 1 Priority 2026-06-17 N/A 4.3 MEDIUM
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41697 1 Priority-software 1 Priority 2026-06-17 N/A 6.1 MEDIUM
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-41696 2026-06-17 N/A 7.5 HIGH
Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41695 2026-06-17 N/A 7.5 HIGH
Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory
CVE-2024-41694 2026-06-17 N/A 5.3 MEDIUM
Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-41693 1 Priority-software 1 Mashov 2026-06-17 N/A 6.1 MEDIUM
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-41692 2026-06-17 N/A N/A
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.
CVE-2024-41691 1 Syrotech 2 Sy-gpon-1110-wdont, Sy-gpon-1110-wdont Firmware 2026-06-17 N/A 4.6 MEDIUM
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext FTP credentials from the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the FTP server associated with the targeted system.