Vulnerabilities (CVE)

Total 398401 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25851 1 Netis-systems 2 Wf2780, Wf2780 Firmware 2026-06-17 N/A 8.0 HIGH
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.
CVE-2024-25850 1 Netis-systems 2 Wf2780, Wf2780 Firmware 2026-06-17 N/A 9.8 CRITICAL
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
CVE-2024-25849 1 Prestatoolkit 1 Make An Offer\/offer Your Price 2026-06-17 N/A 9.8 CRITICAL
In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .
CVE-2024-25848 1 Team-ever 1 Seo 2026-06-17 N/A 5.9 MEDIUM
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25847 1 Myprestamodules 1 Product Catalog \(csv\, Excel\) Import 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
CVE-2024-25846 1 Myprestamodules 1 Product Catalog \(csv\, Excel\) Import 2026-06-17 N/A 9.1 CRITICAL
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
CVE-2024-25845 1 Cleanpresta 1 Cd Custom Fields 4 Orders 2026-06-17 N/A 9.8 CRITICAL
In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25844 1 Common-services 1 So Flexibilite 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.
CVE-2024-25843 1 Prestashop 1 Import\/update Bulk Product 2026-06-17 N/A 9.8 CRITICAL
In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25842 1 Prestaworld 1 Account Manager 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods.
CVE-2024-25841 1 Common-services 1 So Flexibilite 2026-06-17 N/A 5.9 MEDIUM
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
CVE-2024-25840 1 Prestaworld 1 Account Manager 2026-06-17 N/A 7.5 HIGH
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
CVE-2024-25839 1 Webbax 1 Super Newsletter 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information.
CVE-2024-25837 1 Octobercms 1 October 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section.
CVE-2024-25833 1 F-logic 1 Datacube3 2026-06-17 N/A 9.8 CRITICAL
F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.
CVE-2024-25832 1 F-logic 1 Datacube3 2026-06-17 N/A 8.8 HIGH
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
CVE-2024-25831 1 F-logic 1 Datacube3 2026-06-17 N/A 5.4 MEDIUM
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface.
CVE-2024-25830 1 F-logic 2 Datacube3, Datacube3 Firmware 2026-06-17 N/A 9.8 CRITICAL
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.
CVE-2024-25828 1 Cmseasy 1 Cmseasy 2026-06-17 N/A 4.9 MEDIUM
cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
CVE-2024-25825 2026-06-17 N/A 9.8 CRITICAL
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.