Medium · CVSS 5.3
Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve logs with sensitive system.
Published Oct 21, 2024 · Updated Jul 5, 2026
Medium · CVSS 4.3
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver allows remote, unauthenticated attackers to leak memory addresses of uClibc and the stack via sending a GET request to the index page.
Published Oct 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to execute arbitrary code by injecting shell commands into the name of the Vilo device.
Published Oct 21, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.3
A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to enumerate the existence and length of any file in the filesystem by placing malicious payloads in the path of any HTTP request.
Published Oct 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.6
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remote, unauthenticated attackers to gain administrative access over the router.
Published Oct 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.6
A Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via a password field larger than 64 bytes in length.
Published Oct 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.6
A Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via pppoe_username and pppoe_password fields being larger than 128 bytes in length.
Published Oct 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.6
A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via exceptionally long HTTP methods or paths.
Published Oct 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.6
A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via sscanf reading the token and timezone JSON fields into a fixed-length buffer.
Published Oct 21, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process
Published Oct 11, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process
Published Oct 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process
Published Oct 11, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.4
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
Published Oct 16, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
Published Oct 16, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.
Published Oct 11, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.
Published Oct 7, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
Published Oct 9, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.
Published Oct 11, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.6
OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.
Published Oct 7, 2024 · Updated Jul 5, 2026
High · CVSS 7.1
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
Published Oct 7, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe.
Published Oct 7, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.
Published Oct 7, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.
Published Oct 7, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.
Published Oct 7, 2024 · Updated Jul 5, 2026
High · CVSS 8
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
Published Oct 1, 2024 · Updated Jul 5, 2026
High · CVSS 7.6
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
Published Sep 24, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.5
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
Published Sep 30, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.9
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
Published Sep 19, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
Published Sep 9, 2024 · Updated Jul 5, 2026
High · CVSS 8
Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.
Published Sep 10, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
Published Sep 11, 2024 · Updated Jul 5, 2026
Low · CVSS 3.7
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
Published Sep 11, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
Published Sep 11, 2024 · Updated Jul 5, 2026
Medium · CVSS 4.7
A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Sep 11, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
Published Sep 11, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
Published Sep 11, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.
Published Sep 11, 2024 · Updated Jul 5, 2026
High · CVSS 7.2
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
Published Aug 30, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.4
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.
Published Aug 26, 2024 · Updated Jul 5, 2026
High · CVSS 8
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
Published Aug 26, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
Published Aug 26, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
Published Aug 26, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.
Published Aug 26, 2024 · Updated Jul 5, 2026
High · CVSS 7.4
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Published Aug 29, 2024 · Updated Jul 5, 2026
High · CVSS 7.4
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Published Aug 29, 2024 · Updated Jul 5, 2026
High · CVSS 7.4
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Published Aug 29, 2024 · Updated Jul 5, 2026