Vulnerabilities (CVE)

Total 398478 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23059 1 Totolink 2 A3300r, A3300r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.
CVE-2024-23058 1 Totolink 2 A3300r, A3300r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.
CVE-2024-23057 1 Totolink 2 A3300r, A3300r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.
CVE-2024-23049 1 B3log 1 Symphony 2026-06-17 N/A 9.8 CRITICAL
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
CVE-2024-23034 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
CVE-2024-23033 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
CVE-2024-23032 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
CVE-2024-23031 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
CVE-2024-22988 1 Zkteco 1 Zkbio Wdms 2026-06-17 N/A 9.8 CRITICAL
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.
CVE-2024-22957 1 Swftools 1 Swftools 2026-06-17 N/A 5.5 MEDIUM
swftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.
CVE-2024-22956 1 Swftools 1 Swftools 2026-06-17 N/A 7.8 HIGH
swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838
CVE-2024-22955 1 Swftools 1 Swftools 2026-06-17 N/A 7.8 HIGH
swftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576.
CVE-2024-22942 1 Totolink 2 A3300r, A3300r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.
CVE-2024-22939 1 Sunkaifei 1 Flycms 2026-06-17 N/A 8.8 HIGH
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
CVE-2024-22938 1 Bosscms 1 Bosscms 2026-06-17 N/A 7.8 HIGH
Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.
CVE-2024-22936 1 Manuelaldape 1 Parents \& Student Portal 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CVE-2024-22927 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
CVE-2024-22923 1 Advradius 1 Adv Radius 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.
CVE-2024-22920 1 Swftools 1 Swftools 2026-06-17 N/A 7.8 HIGH
swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.
CVE-2024-22919 1 Swftools 1 Swftools 2026-06-17 N/A 7.8 HIGH
swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.