Total
395947 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-41315 | 1 Totolink | 2 A6000r, A6000r Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. | |||||
| CVE-2024-41314 | 1 Totolink | 2 A6000r, A6000r Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function. | |||||
| CVE-2024-41311 | 2 Debian, Struktur | 2 Debian Linux, Libheif | 2026-06-17 | N/A | 8.1 HIGH |
| In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. | |||||
| CVE-2024-41310 | 1 Yanzhenjie | 1 Andserver | 2026-06-17 | N/A | 7.5 HIGH |
| AndServer 2.1.12 is vulnerable to Directory Traversal. | |||||
| CVE-2024-41309 | 1 Enjayworld | 1 Enjay Crm | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system. | |||||
| CVE-2024-41308 | 1 Enjayworld | 1 Enjay Crm | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system. | |||||
| CVE-2024-41305 | 1 Wondercms | 1 Wondercms | 2026-06-17 | N/A | 4.7 MEDIUM |
| A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter. | |||||
| CVE-2024-41304 | 1 Wondercms | 1 Wondercms | 2026-06-17 | N/A | 5.4 MEDIUM |
| An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file. | |||||
| CVE-2024-41290 | 1 Flatpress | 1 Flatpress | 2026-06-17 | N/A | 8.1 HIGH |
| FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component. | |||||
| CVE-2024-41285 | 1 Fastcom | 2 Fw300r, Fw300r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path. | |||||
| CVE-2024-41281 | 1 Linksys | 2 Wrt54g, Wrt54g Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function. | |||||
| CVE-2024-41276 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request limiting mechanism can be easily bypassed, enabling attackers to perform a brute force attack to guess the correct PIN and gain unauthorized access to the application. | |||||
| CVE-2024-41270 | 1 Appleboy | 1 Gorush | 2026-06-17 | N/A | 9.1 CRITICAL |
| An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version. | |||||
| CVE-2024-41265 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. | |||||
| CVE-2024-41264 | 1 Casbin | 1 Casdoor | 2026-06-17 | N/A | 7.5 HIGH |
| An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. | |||||
| CVE-2024-41262 | 1 Codenotary | 1 Immudb | 2026-06-17 | N/A | 7.4 HIGH |
| mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack. | |||||
| CVE-2024-41260 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database. | |||||
| CVE-2024-41259 | 1 Navidrome | 1 Navidrome | 2026-06-17 | N/A | 9.1 CRITICAL |
| Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information. | |||||
| CVE-2024-41258 | 1 Filestash | 1 Filestash | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack. | |||||
| CVE-2024-41256 | 1 Filestash | 1 Filestash | 2026-06-17 | N/A | 5.9 MEDIUM |
| Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack. | |||||
