Vulnerabilities (CVE)

Total 398483 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-22734 1 Amcsgroup 1 Trux Waste Management 2026-06-17 N/A 6.2 MEDIUM
An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components.
CVE-2024-22733 1 Tp-link 2 Mr200, Mr200 Firmware 2026-06-17 N/A 7.5 HIGH
TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.
CVE-2024-22729 1 Netis-systems 2 Mw5360, Mw5360 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
CVE-2024-22727 1 Teltonika 10 Trb140, Trb140 Firmware, Trb141 and 7 more 2026-06-17 N/A 8.3 HIGH
Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability via Ethernet LAN or USB.
CVE-2024-22725 1 Orthanc-server 1 Orthanc 2026-06-17 N/A 6.1 MEDIUM
Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
CVE-2024-22724 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 6.6 MEDIUM
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
CVE-2024-22723 1 Webtrees 1 Webtrees 2026-06-17 N/A 4.9 MEDIUM
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.
CVE-2024-22722 1 Formtools 1 Form Tools 2026-06-17 N/A 7.2 HIGH
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
CVE-2024-22721 1 Formtools 1 Form Tools 2026-06-17 N/A 6.3 MEDIUM
Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.
CVE-2024-22720 1 Kanboard 1 Kanboard 2026-06-17 N/A 4.8 MEDIUM
Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
CVE-2024-22719 1 Formtools 1 Form Tools 2026-06-17 N/A 8.1 HIGH
SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.
CVE-2024-22718 1 Formtools 1 Form Tools 2026-06-17 N/A 9.6 CRITICAL
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.
CVE-2024-22717 1 Formtools 1 Form Tools 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.
CVE-2024-22715 1 Codelyfe 1 Stupid Simple Cms 2026-06-17 N/A 8.8 HIGH
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
CVE-2024-22714 1 Codelyfe 1 Stupid Simple Cms 2026-06-17 N/A 6.1 MEDIUM
Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.
CVE-2024-22705 1 Linux 1 Linux Kernel 2026-06-17 N/A 7.8 HIGH
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.
CVE-2024-22699 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
CVE-2024-22667 2 Fedoraproject, Vim 2 Fedora, Vim 2026-06-17 N/A 7.8 HIGH
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
CVE-2024-22663 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
CVE-2024-22662 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules