Vulnerabilities (CVE)

Total 396909 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-31820 1 Ecommerce-codeigniter-bootstrap Project 1 Ecommerce-codeigniter-bootstrap 2026-06-17 N/A 9.8 CRITICAL
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
CVE-2024-31819 1 Wwbn 1 Avideo 2026-06-17 N/A 9.8 CRITICAL
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
CVE-2024-31818 1 Derbynet 1 Derbynet 2026-06-17 N/A 9.8 CRITICAL
Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.
CVE-2024-31817 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 7.5 HIGH
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
CVE-2024-31816 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 7.5 HIGH
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
CVE-2024-31815 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 9.1 CRITICAL
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
CVE-2024-31814 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
CVE-2024-31813 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 8.4 HIGH
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
CVE-2024-31812 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 6.5 MEDIUM
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.
CVE-2024-31811 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 8.0 HIGH
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
CVE-2024-31810 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2024-31809 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
CVE-2024-31808 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 8.8 HIGH
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
CVE-2024-31807 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
CVE-2024-31806 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 6.5 MEDIUM
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.
CVE-2024-31805 1 Totolink 2 Ex200, Ex200 Firmware 2026-06-17 N/A 6.5 MEDIUM
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.
CVE-2024-31804 2026-06-17 N/A 6.7 MEDIUM
An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.
CVE-2024-31803 2026-06-17 N/A 6.2 MEDIUM
Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT<T>::read_pre_data128_from_file function.
CVE-2024-31802 2026-06-17 N/A 6.3 MEDIUM
DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.
CVE-2024-31801 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive information via a crafted request.