Vulnerabilities (CVE)

Total 396876 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33383 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 7.5 HIGH
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
CVE-2024-33382 1 Open5gs 1 Open5gs 2026-06-17 N/A 5.3 MEDIUM
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVE-2024-33377 1 Lb-link 2 Bl-w1210m, Bl-w1210m Firmware 2026-06-17 N/A 8.1 HIGH
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.
CVE-2024-33375 1 Lb-link 2 Bl-w1210m, Bl-w1210m Firmware 2026-06-17 N/A 9.8 CRITICAL
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
CVE-2024-33374 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.
CVE-2024-33373 1 Lb-link 2 Bl-w1210m, Bl-w1210m Firmware 2026-06-17 N/A 6.3 MEDIUM
An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can allow attackers to access the router via a brute-force attack.
CVE-2024-33371 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.
CVE-2024-33369 1 Plasmoapp 1 Rpshare 2026-06-17 N/A 8.8 HIGH
Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromConnection method in DownloadTask
CVE-2024-33368 1 Plasmoapp 1 Rpshare 2026-06-17 N/A 8.8 HIGH
An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen
CVE-2024-33365 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 7.5 HIGH
Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the Virtual_Data_Check function in the bin/httpd component.
CVE-2024-33350 1 Taogogo 1 Taocms 2026-06-17 N/A 9.8 CRITICAL
Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information via the include/model/file.php component.
CVE-2024-33345 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-33344 1 Dlink 2 Dir-822\+, Dir-822\+ Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.
CVE-2024-33343 1 Dlink 2 Dir-822\+, Dir-822\+ Firmware 2026-06-17 N/A 8.8 HIGH
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.
CVE-2024-33342 1 Dlink 2 Dir-822\+, Dir-822\+ Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.
CVE-2024-33338 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 7.3 HIGH
Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.
CVE-2024-33335 2026-06-17 N/A 6.3 MEDIUM
SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.
CVE-2024-33332 1 Bladex 1 Springblade 2026-06-17 N/A 7.5 HIGH
An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.
CVE-2024-33329 2026-06-17 N/A 7.5 HIGH
A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.
CVE-2024-33328 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter.