Total
398483 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-22660 | 1 Totolink | 2 A3700r, A3700r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg | |||||
| CVE-2024-22654 | 1 Broadcom | 1 Tcpreplay | 2026-06-17 | N/A | 7.5 HIGH |
| tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c. | |||||
| CVE-2024-22653 | 1 Yasm Project | 1 Yasm | 2026-06-17 | N/A | 4.8 MEDIUM |
| yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c. | |||||
| CVE-2024-22651 | 1 Dlink | 2 Dir-815, Dir-815 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04. | |||||
| CVE-2024-22648 | 1 Seopanel | 1 Seo Panel | 2026-06-17 | N/A | 5.3 MEDIUM |
| A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment. | |||||
| CVE-2024-22647 | 1 Seopanel | 1 Seo Panel | 2026-06-17 | N/A | 5.3 MEDIUM |
| An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames. | |||||
| CVE-2024-22646 | 1 Seopanel | 1 Seo Panel | 2026-06-17 | N/A | 5.3 MEDIUM |
| An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system. | |||||
| CVE-2024-22643 | 1 Seopanel | 1 Seo Panel | 2026-06-17 | N/A | 6.5 MEDIUM |
| A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets. | |||||
| CVE-2024-22641 | 1 Tcpdf Project | 1 Tcpdf | 2026-06-17 | N/A | 7.5 HIGH |
| TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. | |||||
| CVE-2024-22640 | 2 Fedoraproject, Tcpdf Project | 2 Fedora, Tcpdf | 2026-06-17 | N/A | 7.5 HIGH |
| TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color. | |||||
| CVE-2024-22639 | 1 Igalerie | 1 Igalerie | 2026-06-17 | N/A | 6.1 MEDIUM |
| iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface. | |||||
| CVE-2024-22638 | 1 Livesite | 1 Livesite | 2026-06-17 | N/A | 9.8 CRITICAL |
| liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php. | |||||
| CVE-2024-22637 | 1 Formtools | 1 Form Tools | 2026-06-17 | N/A | 6.1 MEDIUM |
| Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2. | |||||
| CVE-2024-22636 | 1 Pluxml | 1 Pluxml | 2026-06-17 | N/A | 8.8 HIGH |
| PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field. | |||||
| CVE-2024-22635 | 1 Webcalendar Project | 1 Webcalendar | 2026-06-17 | N/A | 6.1 MEDIUM |
| WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php. | |||||
| CVE-2024-22633 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request. | |||||
| CVE-2024-22632 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request. | |||||
| CVE-2024-22628 | 1 Oretnom23 | 1 Budget And Expense Tracker System | 2026-06-17 | N/A | 7.2 HIGH |
| Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end= | |||||
| CVE-2024-22627 | 1 Campcodes | 1 Supplier Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=. | |||||
| CVE-2024-22626 | 1 Campcodes | 1 Supplier Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retailer.php?id=. | |||||
