CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-50858

    Last Modified: 6 Jun 2025

    Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.

    Published: 14 Jan 2025
    4.8
    Medium

    CVE-2024-50859

    Last Modified: 6 Jun 2025

    The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

    Published: 14 Jan 2025
    6.1
    Medium

    CVE-2024-50861

    Last Modified: 6 Jun 2025

    The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

    Published: 14 Jan 2025
    8.7
    High

    CVE-2024-53561

    Last Modified: 15 Apr 2026

    A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-57473

    Last Modified: 27 May 2025

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-57479

    Last Modified: 27 May 2025

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-57480

    Last Modified: 27 May 2025

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-57482

    Last Modified: 27 May 2025

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-57483

    Last Modified: 9 Apr 2025

    Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57615

    Last Modified: 10 Apr 2025

    An issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57616

    Last Modified: 10 Apr 2025

    An issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57617

    Last Modified: 10 Apr 2025

    An issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57618

    Last Modified: 10 Apr 2025

    An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57620

    Last Modified: 10 Apr 2025

    An issue in the trimchars component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57621

    Last Modified: 10 Apr 2025

    An issue in the GDKanalytical_correlation component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57622

    Last Modified: 10 Apr 2025

    An issue in the exp_bin component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57623

    Last Modified: 10 Apr 2025

    An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57624

    Last Modified: 10 Apr 2025

    An issue in the exp_atom component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57626

    Last Modified: 10 Apr 2025

    An issue in the mat_join2 component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57627

    Last Modified: 10 Apr 2025

    An issue in the gc_col component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57628

    Last Modified: 10 Apr 2025

    An issue in the exp_values_set_supertype component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57629

    Last Modified: 10 Apr 2025

    An issue in the tail_type component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57630

    Last Modified: 10 Apr 2025

    An issue in the exps_card component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57636

    Last Modified: 17 Apr 2025

    An issue in the itc_sample_row_check component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57638

    Last Modified: 17 Apr 2025

    An issue in the dfe_body_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57632

    Last Modified: 10 Apr 2025

    An issue in the is_column_unique component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57633

    Last Modified: 10 Apr 2025

    An issue in the exps_bind_column component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57634

    Last Modified: 10 Apr 2025

    An issue in the exp_copy component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57640

    Last Modified: 17 Apr 2025

    An issue in the dc_add_int component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57641

    Last Modified: 17 Apr 2025

    An issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57642

    Last Modified: 17 Apr 2025

    An issue in the dfe_inx_op_col_def_table component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57643

    Last Modified: 17 Apr 2025

    An issue in the box_deserialize_string component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57644

    Last Modified: 17 Apr 2025

    An issue in the itc_hash_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57646

    Last Modified: 17 Apr 2025

    An issue in the psiginfo component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57648

    Last Modified: 17 Apr 2025

    An issue in the itc_set_param_row component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57649

    Last Modified: 17 Apr 2025

    An issue in the qst_vec_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57650

    Last Modified: 17 Apr 2025

    An issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57652

    Last Modified: 17 Apr 2025

    An issue in the numeric_to_dv component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57653

    Last Modified: 17 Apr 2025

    An issue in the qst_vec_set_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57654

    Last Modified: 17 Apr 2025

    An issue in the qst_vec_get_int64 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57655

    Last Modified: 17 Apr 2025

    An issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57656

    Last Modified: 17 Apr 2025

    An issue in the sqlc_add_distinct_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57657

    Last Modified: 17 Apr 2025

    An issue in the sqlg_vec_upd component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57659

    Last Modified: 17 Apr 2025

    An issue in the sqlg_parallel_ts_seq component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57660

    Last Modified: 17 Apr 2025

    An issue in the sqlo_expand_jts component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57661

    Last Modified: 17 Apr 2025

    An issue in the sqlo_df component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57662

    Last Modified: 17 Apr 2025

    An issue in the sqlg_hash_source component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57663

    Last Modified: 17 Apr 2025

    An issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57757

    Last Modified: 18 Apr 2025

    JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

    Published: 14 Jan 2025
    6.5
    Medium

    CVE-2024-57760

    Last Modified: 21 Apr 2025

    JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.

    Published: 14 Jan 2025