Vulnerabilities (CVE)

Total 398385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28397 2026-06-17 N/A 5.3 MEDIUM
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
CVE-2024-28396 1 Myprestamodules 1 Orders \(csv\, Excel\) Export Pro 2026-06-17 N/A 7.5 HIGH
An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.
CVE-2024-28395 1 Best-kit 1 Bestkit Popup 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.
CVE-2024-28394 2026-06-17 N/A 9.8 CRITICAL
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.
CVE-2024-28393 1 Scalapay 1 Scalapay 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.
CVE-2024-28392 1 Prestashop 1 Abandoned Cart Reminder Pro 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.
CVE-2024-28391 1 Fmemodules 1 B2b Quick Order Form 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.
CVE-2024-28390 1 Advancedplugins 1 Ultimateimagetool 2026-06-17 N/A 9.8 CRITICAL
An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.
CVE-2024-28389 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.
CVE-2024-28388 1 Sunnytoo 1 Product Comments 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.
CVE-2024-28387 1 Axonaut 1 Axonaut 2026-06-17 N/A 7.5 HIGH
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.
CVE-2024-28383 1 Tenda 2 Ax12, Ax12 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.
CVE-2024-28354 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 10.0 CRITICAL
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2024-28353 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 8.8 HIGH
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2024-28345 1 Sipwise 1 Next Generation Communication Platform 2026-06-17 N/A 5.5 MEDIUM
An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL.
CVE-2024-28344 1 Sipwise 1 Next Generation Communication Platform 2026-06-17 N/A 3.1 LOW
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.
CVE-2024-28340 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 7.5 HIGH
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-28339 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 5.4 MEDIUM
An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-28338 1 Totolink 2 A8000ru, A8000ru Firmware 2026-06-17 N/A 8.0 HIGH
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
CVE-2024-28335 2026-06-17 N/A 9.1 CRITICAL
Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.