Total
398483 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-22547 | 1 Wayos | 2 Ibr-7150, Ibr-7150 Firmware | 2026-06-17 | N/A | 4.7 MEDIUM |
| WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2024-22546 | 1 Trendnet | 2 Tew-815dap, Tew-815dap Firmware | 2026-06-17 | N/A | 6.4 MEDIUM |
| TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request. | |||||
| CVE-2024-22545 | 1 Trendnet | 2 Tew-824dru, Tew-824dru Firmware | 2026-06-17 | N/A | 7.8 HIGH |
| An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely. | |||||
| CVE-2024-22544 | 1 Linksys | 2 E1700, E1700 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function. | |||||
| CVE-2024-22543 | 1 Linksys | 2 E1700, E1700 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function. | |||||
| CVE-2024-22533 | 1 Xiandafu | 1 Beetl | 2026-06-17 | N/A | 9.8 CRITICAL |
| Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution. | |||||
| CVE-2024-22532 | 1 Xnview | 1 Nconvert | 2026-06-17 | N/A | 6.5 MEDIUM |
| Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file. | |||||
| CVE-2024-22529 | 1 Totolink | 2 X2000r, X2000r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa. | |||||
| CVE-2024-22526 | 1 Bandisoft | 1 Bandiview | 2026-06-17 | N/A | 5.5 MEDIUM |
| Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file. | |||||
| CVE-2024-22525 | 1 Dnspod | 1 Dnspod Security Recursive | 2026-06-17 | N/A | 5.5 MEDIUM |
| dnspod-sr 0dfbd37 contains a SEGV. | |||||
| CVE-2024-22524 | 1 Dnspod | 1 Dnspod Security Recursive | 2026-06-17 | N/A | 5.5 MEDIUM |
| dnspod-sr 0dfbd37 is vulnerable to buffer overflow. | |||||
| CVE-2024-22523 | 1 Fuwushe | 1 Ifair | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component. | |||||
| CVE-2024-22520 | 1 Dronetag | 1 Drone Scanner | 2026-06-17 | N/A | 8.2 HIGH |
| An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets. | |||||
| CVE-2024-22519 | 1 Sorenfriis | 1 Opendroneid Osm | 2026-06-17 | N/A | 8.2 HIGH |
| An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets. | |||||
| CVE-2024-22515 | 1 Ispyconnect | 1 Agent Dvr | 2026-06-17 | N/A | 8.8 HIGH |
| Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component. | |||||
| CVE-2024-22514 | 1 Ispyconnect | 1 Agent Dvr | 2026-06-17 | N/A | 8.8 HIGH |
| An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file. | |||||
| CVE-2024-22513 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method. | |||||
| CVE-2024-22497 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL. | |||||
| CVE-2024-22496 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter. | |||||
| CVE-2024-22494 | 1 Jfinalcms Project | 1 Jfinalcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to inject arbitrary web script or HTML. | |||||
