Total
395957 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-40417 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow. | |||||
| CVE-2024-40416 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow. | |||||
| CVE-2024-40415 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow. | |||||
| CVE-2024-40414 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow. | |||||
| CVE-2024-40412 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function. | |||||
| CVE-2024-40410 | 1 Cybelesoft | 1 Thinfinity Workspace | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption. | |||||
| CVE-2024-40408 | 1 Cybelesoft | 1 Thinfinity Workspace | 2026-06-17 | N/A | 7.3 HIGH |
| Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges. | |||||
| CVE-2024-40407 | 1 Cybelesoft | 1 Thinfinity Workspace | 2026-06-17 | N/A | 7.5 HIGH |
| A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors. | |||||
| CVE-2024-40405 | 1 Cybelesoft | 1 Thinfinity Workspace | 2026-06-17 | N/A | 8.1 HIGH |
| Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request. | |||||
| CVE-2024-40404 | 1 Cybelesoft | 1 Thinfinity Workspace | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established. | |||||
| CVE-2024-40402 | 1 Nikhil-bhalerao | 1 Simple Library Management System | 2026-06-17 | N/A | 6.3 MEDIUM |
| A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries. | |||||
| CVE-2024-40400 | 1 Automad | 1 Automad | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file. | |||||
| CVE-2024-40395 | 1 Ptc | 1 Thingworx | 2026-06-17 | N/A | 6.5 MEDIUM |
| An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level. | |||||
| CVE-2024-40394 | 1 Oretnom23 | 1 Simple Library Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php. | |||||
| CVE-2024-40393 | 1 Angeljudesuarez | 1 Online Clinic Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php. | |||||
| CVE-2024-40392 | 1 Fkgeo | 1 Pharmacy\/medical Store Point Of Sale System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php. | |||||
| CVE-2024-40348 | 1 Bazarr | 1 Bazarr | 2026-06-17 | N/A | 8.2 HIGH |
| An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. | |||||
| CVE-2024-40347 | 1 Hyland | 1 Alfresco Content Services | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter htmlid. | |||||
| CVE-2024-40336 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 6.1 MEDIUM |
| idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.' | |||||
| CVE-2024-40334 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.8 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3 | |||||
