Medium · CVSS 5.3
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules
Published May 28, 2024 · Updated Jul 9, 2026
High · CVSS 8.8
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth
Published May 28, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setMacFilterRules.
Published May 28, 2024 · Updated Jul 9, 2026
High · CVSS 8.8
TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published May 28, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
Published May 24, 2024 · Updated Jul 9, 2026
High · CVSS 8.8
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
Published May 24, 2024 · Updated Jul 9, 2026
High · CVSS 7.5
The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong MAV_MISSION_TYPE.
Published May 3, 2024 · Updated Jul 9, 2026
High · CVSS 7.5
An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive information via the uploadfiles.php component.
Published Apr 30, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
Published May 7, 2024 · Updated Jul 9, 2026
High · CVSS 7.1
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
Published Apr 19, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.9
An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.
Published May 2, 2024 · Updated Jul 9, 2026
Medium · CVSS 4.6
A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.
Published Apr 19, 2024 · Updated Jul 9, 2026
Medium · CVSS 4.3
CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.
Published Apr 17, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
jizhiCMS 2.5 suffers from a File upload vulnerability.
Published Apr 17, 2024 · Updated Jul 9, 2026
Low · CVSS 3.9
An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.
Published May 3, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.
Published Mar 28, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.5
SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.
Published May 10, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.
Published Mar 26, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.
Published Mar 29, 2024 · Updated Jul 9, 2026
High · CVSS 8.8
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.
Published Apr 3, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.3
A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.
Published Apr 10, 2024 · Updated Jul 9, 2026
High · CVSS 8.1
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
Published Mar 20, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.3
Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
Published Apr 22, 2024 · Updated Jul 9, 2026
High · CVSS 8.1
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
Published Mar 28, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.
Published Mar 28, 2024 · Updated Jul 9, 2026
High · CVSS 7.8
A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function.
Published Apr 22, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.
Published Mar 25, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.4
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.
Published Apr 26, 2024 · Updated Jul 9, 2026
High · CVSS 8.4
Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.
Published Apr 26, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.8
Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART interface.
Published Apr 26, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.
Published Apr 26, 2024 · Updated Jul 9, 2026
High · CVSS 7.5
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.
Published Apr 6, 2024 · Updated Jul 9, 2026
High · CVSS 7.3
Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to ram causing buffer overflow if file or files uploaded are greater than available ram. Ftp server allows change of directory to root which is one level up than root of usb flash directory. During upload ram is getting filled and causing system resource exhaustion (no free memory) which causes system to crash and reboot.
Published Mar 29, 2024 · Updated Jul 9, 2026
High · CVSS 8.2
An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.
Published Mar 7, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.
Published May 14, 2024 · Updated Jul 9, 2026
High · CVSS 7
An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.
Published Feb 22, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.1
Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.
Published Apr 26, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.1
An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.
Published Mar 20, 2024 · Updated Jul 9, 2026
High · CVSS 7.8
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
Published Feb 29, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
Published Feb 6, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.4
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.
Published Feb 5, 2024 · Updated Jul 9, 2026
Medium · CVSS 6.1
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
Published Feb 5, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
Published Feb 8, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.8
Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 8, 2024 · Updated Jul 9, 2026
High · CVSS 7.5
Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 8, 2024 · Updated Jul 9, 2026
High · CVSS 7.5
Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 8, 2024 · Updated Jul 9, 2026
Medium · CVSS 5.3
Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatUtils::useDefaultWeekmodel(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 10, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 8, 2024 · Updated Jul 9, 2026
Unknown · CVSS Not scored
ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 8, 2024 · Updated Jul 9, 2026
Critical · CVSS 9.1
Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Published Apr 10, 2024 · Updated Jul 9, 2026