Vulnerabilities (CVE)

Total 396026 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39209 2026-06-17 N/A 6.3 MEDIUM
luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.
CVE-2024-39208 2026-06-17 N/A 9.8 CRITICAL
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
CVE-2024-39207 2026-06-17 N/A 8.2 HIGH
lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.
CVE-2024-39206 2026-06-17 N/A 7.5 HIGH
An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key.
CVE-2024-39205 2026-06-17 N/A 9.8 CRITICAL
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
CVE-2024-39203 1 Zblogcn 1 Z-blogphp 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-39202 1 Dlink 2 Dir-823x Ax3000, Dir-823x Ax3000 Firmware 2026-06-17 N/A 8.8 HIGH
D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings.
CVE-2024-39182 2026-06-17 N/A 7.5 HIGH
An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root user's session via an arbitrary command (ISP6-1779).
CVE-2024-39181 1 Szlbt 2 Lbt-t300-t400, Lbt-t300-t400 Firmware 2026-06-17 N/A 6.5 MEDIUM
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegenerate_conf_router() function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-39178 2026-06-17 N/A 5.4 MEDIUM
MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump/tcpdump.php?menu_uuid.
CVE-2024-39174 1 Yzmcms 1 Yzmcms 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.
CVE-2024-39173 2026-06-17 N/A 9.8 CRITICAL
calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.
CVE-2024-39165 2026-06-17 N/A 9.8 CRITICAL
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
CVE-2024-39163 2026-06-17 N/A 8.8 HIGH
binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.
CVE-2024-39162 2026-06-17 N/A 6.1 MEDIUM
pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2024-39158 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.
CVE-2024-39157 1 Idccms 1 Idccms 2026-06-17 N/A 3.8 LOW
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.
CVE-2024-39156 1 Idccms 1 Idccms 2026-06-17 N/A 3.8 LOW
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.
CVE-2024-39155 1 Idccms 1 Idccms 2026-06-17 N/A 6.8 MEDIUM
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.
CVE-2024-39154 1 Idccms 1 Idccms 2026-06-17 N/A 8.8 HIGH
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.