Vulnerabilities (CVE)

Total 395957 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40113 1 Sitecom 2 Wlx-2006, Wlx-2006 Firmware 2026-06-17 N/A 6.5 MEDIUM
Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.
CVE-2024-40112 1 Sitecom 2 Wlx-2006, Wlx-2006 Firmware 2026-06-17 N/A 5.9 MEDIUM
A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the "language" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.
CVE-2024-40111 1 Automad 1 Automad 2026-06-17 N/A 4.8 MEDIUM
A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.
CVE-2024-40110 1 Nikhil-bhalerao 1 Poultry Farm Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.
CVE-2024-40096 1 Rd Labs Llc 1 Who 2026-06-17 N/A 3.3 LOW
The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.
CVE-2024-40094 2026-06-17 N/A 5.3 MEDIUM
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
CVE-2024-40075 2026-06-17 N/A 4.3 MEDIUM
Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.
CVE-2024-40074 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 4.8 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.
CVE-2024-40073 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
CVE-2024-40072 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
CVE-2024-40071 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40070 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 5.1 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40069 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 5.4 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.
CVE-2024-40068 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 5.9 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.
CVE-2024-40060 1 Wcharczuk 1 Go-chart 2026-06-17 N/A 7.5 HIGH
go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
CVE-2024-40051 1 Ip-guard 1 Ip-guard 2026-06-17 N/A 7.5 HIGH
IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.
CVE-2024-40039 1 Idccms Project 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del
CVE-2024-40038 1 Idccms 1 Idccms 2026-06-17 N/A 5.3 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev
CVE-2024-40037 1 Idccms Project 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del
CVE-2024-40036 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=add&nohrefStr=close