Total
395945 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-41710 | 1 Mitel | 30 6863i Sip, 6863i Sip Firmware, 6865i Sip and 27 more | 2026-06-17 | N/A | 7.2 HIGH |
| A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system. | |||||
| CVE-2024-41709 | 1 Backdropcms | 1 Backdrop | 2026-06-17 | N/A | 4.8 MEDIUM |
| Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission. | |||||
| CVE-2024-41708 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module. | |||||
| CVE-2024-41707 | 1 Archerirm | 1 Archer | 2026-06-17 | N/A | 4.8 MEDIUM |
| An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. | |||||
| CVE-2024-41706 | 1 Archerirm | 1 Archer | 2026-06-17 | N/A | 7.3 HIGH |
| A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 P4 (6.14.0.4) is also a fixed release. | |||||
| CVE-2024-41705 | 1 Archerirm | 1 Archer | 2026-06-17 | N/A | 7.1 HIGH |
| A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14.P4 (6.14.0.4) and 6.13 P4 (6.13.0.4) are also fixed releases. This vulnerability is similar to, but not identical to, CVE-2023-30639. | |||||
| CVE-2024-41704 | 1 Librechat | 1 Librechat | 2026-06-17 | N/A | 9.8 CRITICAL |
| LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. | |||||
| CVE-2024-41703 | 1 Librechat | 1 Librechat | 2026-06-17 | N/A | 9.8 CRITICAL |
| LibreChat through 0.7.4-rc1 has incorrect access control for message updates. | |||||
| CVE-2024-41702 | 1 Siberiancms | 1 Siberiancms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |||||
| CVE-2024-41701 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-41700 | 1 Barix | 1 Sip Client Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-41699 | 1 Priority-software | 1 Priority | 2026-06-17 | N/A | 4.4 MEDIUM |
| Priority – CWE-552: Files or Directories Accessible to External Parties | |||||
| CVE-2024-41698 | 1 Priority-software | 1 Priority | 2026-06-17 | N/A | 4.3 MEDIUM |
| Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-41697 | 1 Priority-software | 1 Priority | 2026-06-17 | N/A | 6.1 MEDIUM |
| Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | |||||
| CVE-2024-41696 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-41695 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory | |||||
| CVE-2024-41694 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |||||
| CVE-2024-41693 | 1 Priority-software | 1 Mashov | 2026-06-17 | N/A | 6.1 MEDIUM |
| Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | |||||
| CVE-2024-41692 | 2026-06-17 | N/A | N/A | ||
| This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system. | |||||
| CVE-2024-41691 | 1 Syrotech | 2 Sy-gpon-1110-wdont, Sy-gpon-1110-wdont Firmware | 2026-06-17 | N/A | 4.6 MEDIUM |
| This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext FTP credentials from the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the FTP server associated with the targeted system. | |||||
