Vulnerabilities (CVE)

Total 396425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36837 1 Crmeb 1 Crmeb 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
CVE-2024-36832 1 Dlink 2 Dap-1513, Dap-1513 Firmware 2026-06-17 N/A 7.5 HIGH
A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receives a carefully constructed HTTP request, it will crash and exit due to a null pointer reference, leading to a denial of service attack to the device.
CVE-2024-36831 1 Dlink 2 Dap-1520, Dap-1520 Firmware 2026-06-17 N/A 5.3 MEDIUM
A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.
CVE-2024-36829 1 Teldat 2 M1, M1 Firmware 2026-06-17 N/A 7.5 HIGH
Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.
CVE-2024-36827 1 Dnkorpushov 1 Ebookmeta 2026-06-17 N/A 7.5 HIGH
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
CVE-2024-36823 1 Ninjaframework 1 Ninja 2026-06-17 N/A 7.5 HIGH
The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.
CVE-2024-36821 1 Linksys 2 Velop Whw0101, Velop Whw0101 Firmware 2026-06-17 N/A 6.8 MEDIUM
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
CVE-2024-36819 1 Mapos 1 Map-os 2026-06-17 N/A 5.4 MEDIUM
MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.
CVE-2024-36814 2026-06-17 N/A 4.9 MEDIUM
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory.
CVE-2024-36801 1 Sem-cms 1 Semcms 2026-06-17 N/A 5.9 MEDIUM
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
CVE-2024-36800 1 Sem-cms 1 Semcms 2026-06-17 N/A 7.5 HIGH
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.
CVE-2024-36795 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 4.0 MEDIUM
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.
CVE-2024-36792 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.2 HIGH
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
CVE-2024-36790 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
CVE-2024-36789 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.1 HIGH
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
CVE-2024-36788 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 4.8 MEDIUM
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.
CVE-2024-36787 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
CVE-2024-36783 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.
CVE-2024-36782 1 Totolink 2 Cp300, Cp300 Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
CVE-2024-36779 1 Stock Management System Project 1 Stock Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.