Total
398401 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25851 | 1 Netis-systems | 2 Wf2780, Wf2780 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi. | |||||
| CVE-2024-25850 | 1 Netis-systems | 2 Wf2780, Wf2780 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter | |||||
| CVE-2024-25849 | 1 Prestatoolkit | 1 Make An Offer\/offer Your Price | 2026-06-17 | N/A | 9.8 CRITICAL |
| In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` . | |||||
| CVE-2024-25848 | 1 Team-ever | 1 Seo | 2026-06-17 | N/A | 5.9 MEDIUM |
| In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions. | |||||
| CVE-2024-25847 | 1 Myprestamodules | 1 Product Catalog \(csv\, Excel\) Import | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |||||
| CVE-2024-25846 | 1 Myprestamodules | 1 Product Catalog \(csv\, Excel\) Import | 2026-06-17 | N/A | 9.1 CRITICAL |
| In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |||||
| CVE-2024-25845 | 1 Cleanpresta | 1 Cd Custom Fields 4 Orders | 2026-06-17 | N/A | 9.8 CRITICAL |
| In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions. | |||||
| CVE-2024-25844 | 1 Common-services | 1 So Flexibilite | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file. | |||||
| CVE-2024-25843 | 1 Prestashop | 1 Import\/update Bulk Product | 2026-06-17 | N/A | 9.8 CRITICAL |
| In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions. | |||||
| CVE-2024-25842 | 1 Prestaworld | 1 Account Manager | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods. | |||||
| CVE-2024-25841 | 1 Common-services | 1 So Flexibilite | 2026-06-17 | N/A | 5.9 MEDIUM |
| In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection. | |||||
| CVE-2024-25840 | 1 Prestaworld | 1 Account Manager | 2026-06-17 | N/A | 7.5 HIGH |
| In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. | |||||
| CVE-2024-25839 | 1 Webbax | 1 Super Newsletter | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information. | |||||
| CVE-2024-25837 | 1 Octobercms | 1 October | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section. | |||||
| CVE-2024-25833 | 1 F-logic | 1 Datacube3 | 2026-06-17 | N/A | 9.8 CRITICAL |
| F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database. | |||||
| CVE-2024-25832 | 1 F-logic | 1 Datacube3 | 2026-06-17 | N/A | 8.8 HIGH |
| F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | |||||
| CVE-2024-25831 | 1 F-logic | 1 Datacube3 | 2026-06-17 | N/A | 5.4 MEDIUM |
| F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface. | |||||
| CVE-2024-25830 | 1 F-logic | 2 Datacube3, Datacube3 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password. | |||||
| CVE-2024-25828 | 1 Cmseasy | 1 Cmseasy | 2026-06-17 | N/A | 4.9 MEDIUM |
| cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php. | |||||
| CVE-2024-25825 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password. | |||||
