Vulnerabilities (CVE)

Total 398466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24323 1 Linlinjava 1 Litemall 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.
CVE-2024-24320 1 Mgt-commerce 1 Cloudpanel 2026-06-17 N/A 8.8 HIGH
Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the load-logfiles function.
CVE-2024-24313 2026-06-17 N/A 7.5 HIGH
An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/FormModel.php and QRModel.php component.
CVE-2024-24312 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserModel.php component.
CVE-2024-24311 1 Lineagrafica 1 Multilingual And Multistore Sitemap Pro 2026-06-17 N/A 7.5 HIGH
Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction.
CVE-2024-24310 1 Ethercreation 1 Generate Barcode On Invoice \/ Delivery Slip 2026-06-17 N/A 8.8 HIGH
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
CVE-2024-24309 1 Ecomiz 1 Survey Tma 2026-06-17 N/A 7.5 HIGH
In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.
CVE-2024-24308 1 Boostmyshop 1 Boostmyshop 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.
CVE-2024-24307 1 Prestalife 1 Product Designer 2026-06-17 N/A 7.5 HIGH
Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the ajaxProcessCropImage() method.
CVE-2024-24304 1 Sinch 1 Mailjet 2026-06-17 N/A 7.5 HIGH
In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.
CVE-2024-24303 1 Hipresta 1 Gift Wrapping Pro 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.
CVE-2024-24302 1 Prestalife 1 Product Designer 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the postProcess() method.
CVE-2024-24301 1 4ipnet 2 Eap-767, Eap-767 Firmware 2026-06-17 N/A 8.8 HIGH
Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.
CVE-2024-24300 1 4ipnet 2 Eap-767, Eap-767 Firmware 2026-06-17 N/A 9.8 CRITICAL
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.
CVE-2024-24294 2026-06-17 N/A 9.8 CRITICAL
A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.
CVE-2024-24293 2026-06-17 N/A 8.8 HIGH
A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the M function e argument in index.js.
CVE-2024-24292 1 Aliconnect 1 Software Development Kit 2026-06-17 N/A 9.8 CRITICAL
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.
CVE-2024-24291 1 Yzmcms 1 Yzmcms 2026-06-17 N/A 6.1 MEDIUM
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
CVE-2024-24279 1 Secdiskapp 1 Secdiskapp 2026-06-17 N/A 8.8 HIGH
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.
CVE-2024-24278 2 Microsoft, Teamwire 2 Windows, Teamwire 2026-06-17 N/A 7.5 HIGH
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.