Total
395957 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-40333 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.8 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2 | |||||
| CVE-2024-40332 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.8 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord | |||||
| CVE-2024-40331 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.8 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup | |||||
| CVE-2024-40329 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 8.8 HIGH |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup | |||||
| CVE-2024-40328 | 1 Idccms | 1 Idccms | 2026-06-17 | N/A | 6.3 MEDIUM |
| idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6 | |||||
| CVE-2024-40324 | 1 Datex-soft | 1 E-staff | 2026-06-17 | N/A | 5.4 MEDIUM |
| A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation. | |||||
| CVE-2024-40322 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 8.8 HIGH |
| An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data | |||||
| CVE-2024-40318 | 1 Webkul | 1 Qloapps | 2026-06-17 | N/A | 7.2 HIGH |
| An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40317 | 1 Airc | 1 Mynet | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter HTTP. | |||||
| CVE-2024-40239 | 1 Hitbytes | 1 Life | 2026-06-17 | N/A | 6.8 MEDIUM |
| An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function. | |||||
| CVE-2024-40137 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function. | |||||
| CVE-2024-40130 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 9.8 CRITICAL |
| open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c. | |||||
| CVE-2024-40129 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 9.8 CRITICAL |
| Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c. | |||||
| CVE-2024-40125 | 1 Closed-loop | 1 Cless Server | 2026-06-17 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint. | |||||
| CVE-2024-40124 | 1 Pydio | 1 Pydio | 2026-06-17 | N/A | 5.4 MEDIUM |
| Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature. | |||||
| CVE-2024-40120 | 1 Seaweedfs | 1 Seaweedfs | 2026-06-17 | N/A | 6.5 MEDIUM |
| seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go. | |||||
| CVE-2024-40119 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a potential account takeover. | |||||
| CVE-2024-40117 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base. | |||||
| CVE-2024-40116 | 2026-06-17 | N/A | 8.1 HIGH | ||
| An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base. | |||||
| CVE-2024-40114 | 1 Sitecom | 2 Wlx-2006, Wlx-2006 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code. | |||||
