Vulnerabilities (CVE)

Total 398483 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-22547 1 Wayos 2 Ibr-7150, Ibr-7150 Firmware 2026-06-17 N/A 4.7 MEDIUM
WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).
CVE-2024-22546 1 Trendnet 2 Tew-815dap, Tew-815dap Firmware 2026-06-17 N/A 6.4 MEDIUM
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.
CVE-2024-22545 1 Trendnet 2 Tew-824dru, Tew-824dru Firmware 2026-06-17 N/A 7.8 HIGH
An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.
CVE-2024-22544 1 Linksys 2 E1700, E1700 Firmware 2026-06-17 N/A 8.0 HIGH
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.
CVE-2024-22543 1 Linksys 2 E1700, E1700 Firmware 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.
CVE-2024-22533 1 Xiandafu 1 Beetl 2026-06-17 N/A 9.8 CRITICAL
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.
CVE-2024-22532 1 Xnview 1 Nconvert 2026-06-17 N/A 6.5 MEDIUM
Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.
CVE-2024-22529 1 Totolink 2 X2000r, X2000r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.
CVE-2024-22526 1 Bandisoft 1 Bandiview 2026-06-17 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.
CVE-2024-22525 1 Dnspod 1 Dnspod Security Recursive 2026-06-17 N/A 5.5 MEDIUM
dnspod-sr 0dfbd37 contains a SEGV.
CVE-2024-22524 1 Dnspod 1 Dnspod Security Recursive 2026-06-17 N/A 5.5 MEDIUM
dnspod-sr 0dfbd37 is vulnerable to buffer overflow.
CVE-2024-22523 1 Fuwushe 1 Ifair 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.
CVE-2024-22520 1 Dronetag 1 Drone Scanner 2026-06-17 N/A 8.2 HIGH
An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.
CVE-2024-22519 1 Sorenfriis 1 Opendroneid Osm 2026-06-17 N/A 8.2 HIGH
An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.
CVE-2024-22515 1 Ispyconnect 1 Agent Dvr 2026-06-17 N/A 8.8 HIGH
Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.
CVE-2024-22514 1 Ispyconnect 1 Agent Dvr 2026-06-17 N/A 8.8 HIGH
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
CVE-2024-22513 2026-06-17 N/A 5.5 MEDIUM
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.
CVE-2024-22497 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.
CVE-2024-22496 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.
CVE-2024-22494 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 5.4 MEDIUM
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to inject arbitrary web script or HTML.