Vulnerabilities (CVE)

Total 395947 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-41315 1 Totolink 2 A6000r, A6000r Firmware 2026-06-17 N/A 6.8 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
CVE-2024-41314 1 Totolink 2 A6000r, A6000r Firmware 2026-06-17 N/A 6.8 MEDIUM
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
CVE-2024-41311 2 Debian, Struktur 2 Debian Linux, Libheif 2026-06-17 N/A 8.1 HIGH
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
CVE-2024-41310 1 Yanzhenjie 1 Andserver 2026-06-17 N/A 7.5 HIGH
AndServer 2.1.12 is vulnerable to Directory Traversal.
CVE-2024-41309 1 Enjayworld 1 Enjay Crm 2026-06-17 N/A 7.8 HIGH
An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
CVE-2024-41308 1 Enjayworld 1 Enjay Crm 2026-06-17 N/A 7.8 HIGH
An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
CVE-2024-41305 1 Wondercms 1 Wondercms 2026-06-17 N/A 4.7 MEDIUM
A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
CVE-2024-41304 1 Wondercms 1 Wondercms 2026-06-17 N/A 5.4 MEDIUM
An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file.
CVE-2024-41290 1 Flatpress 1 Flatpress 2026-06-17 N/A 8.1 HIGH
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
CVE-2024-41285 1 Fastcom 2 Fw300r, Fw300r Firmware 2026-06-17 N/A 9.8 CRITICAL
A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.
CVE-2024-41281 1 Linksys 2 Wrt54g, Wrt54g Firmware 2026-06-17 N/A 8.8 HIGH
Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
CVE-2024-41276 2026-06-17 N/A 9.8 CRITICAL
A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application.
CVE-2024-41270 1 Appleboy 1 Gorush 2026-06-17 N/A 9.1 CRITICAL
An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.
CVE-2024-41265 2026-06-17 N/A 7.5 HIGH
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.
CVE-2024-41264 1 Casbin 1 Casdoor 2026-06-17 N/A 7.5 HIGH
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
CVE-2024-41262 1 Codenotary 1 Immudb 2026-06-17 N/A 7.4 HIGH
mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.
CVE-2024-41260 2026-06-17 N/A 7.5 HIGH
A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database.
CVE-2024-41259 1 Navidrome 1 Navidrome 2026-06-17 N/A 9.1 CRITICAL
Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.
CVE-2024-41258 1 Filestash 1 Filestash 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
CVE-2024-41256 1 Filestash 1 Filestash 2026-06-17 N/A 5.9 MEDIUM
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.