Total
398387 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27570 | 1 Libtor | 2 Lbt-t300-t390, Lbt-t300-t390 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |||||
| CVE-2024-27569 | 1 Libtor | 2 Lbt-t300-t390, Lbt-t300-t390 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |||||
| CVE-2024-27568 | 1 Libtor | 2 Lbt-t300-t390, Lbt-t300-t390 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |||||
| CVE-2024-27567 | 1 Libtor | 2 Lbt-t300-t390, Lbt-t300-t390 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |||||
| CVE-2024-27565 | 1 Dirk1983 | 1 Chatgpt-wechat-personal | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests. | |||||
| CVE-2024-27564 | 1 Dirk1983 | 1 Chatgpt | 2026-06-17 | N/A | 5.8 MEDIUM |
| pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading. | |||||
| CVE-2024-27563 | 1 Wondercms | 1 Wondercms | 2026-06-17 | N/A | 5.3 MEDIUM |
| A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter. | |||||
| CVE-2024-27561 | 1 Wondercms | 1 Wondercms | 2026-06-17 | N/A | 8.1 HIGH |
| A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter. | |||||
| CVE-2024-27559 | 1 Codelyfe | 1 Stupid Simple Cms | 2026-06-17 | N/A | 6.3 MEDIUM |
| Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php | |||||
| CVE-2024-27558 | 1 Codelyfe | 1 Stupid Simple Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings. | |||||
| CVE-2024-27532 | 1 Bytecodealliance | 1 Webassembly Micro Runtime | 2026-06-17 | N/A | 7.5 HIGH |
| wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types. | |||||
| CVE-2024-27530 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 8.4 HIGH |
| wasm3 139076a contains a Use-After-Free in ForEachModule. | |||||
| CVE-2024-27529 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 8.4 HIGH |
| wasm3 139076a contains memory leaks in Read_utf8. | |||||
| CVE-2024-27528 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 8.4 HIGH |
| wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution. | |||||
| CVE-2024-27527 | 1 Wasm3 Project | 1 Wasm3 | 2026-06-17 | N/A | 7.5 HIGH |
| wasm3 139076a is vulnerable to Denial of Service (DoS). | |||||
| CVE-2024-27525 | 1 Chamilo | 1 Chamilo Lms | 2026-06-17 | N/A | 4.6 MEDIUM |
| Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component. | |||||
| CVE-2024-27524 | 1 Chamilo | 1 Chamilo Lms | 2026-06-17 | N/A | 7.1 HIGH |
| Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component. | |||||
| CVE-2024-27521 | 1 Totolink | 2 A3300r, A3300r Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root"). | |||||
| CVE-2024-27518 | 2026-06-17 | N/A | 7.8 HIGH | ||
| An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder. | |||||
| CVE-2024-27517 | 1 Webasyst | 1 Webasyst | 2026-06-17 | N/A | 5.4 MEDIUM |
| Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code after gaining blog permissions. | |||||
