Vulnerabilities (CVE)

Total 395527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48707 1 O-dyn 1 Collabtive 2026-06-17 N/A 5.4 MEDIUM
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
CVE-2024-48706 1 O-dyn 1 Collabtive 2026-06-17 N/A 5.4 MEDIUM
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
CVE-2024-48704 1 Phpgurukul 1 Medical Card Generation System 2026-06-17 N/A 6.1 MEDIUM
Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.
CVE-2024-48703 1 Anujk305 1 Medical Card Generation System 2026-06-17 N/A 4.8 MEDIUM
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.
CVE-2024-48702 1 Phpgurukul 1 Old Age Home Management System 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.
CVE-2024-48700 1 Kliqqi 1 Kliqqi Cms 2026-06-17 N/A 7.2 HIGH
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
CVE-2024-48694 2026-06-17 N/A 9.8 CRITICAL
File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.
CVE-2024-48662 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component.
CVE-2024-48659 1 Dcnetworks 2 Dcme-320-l, Dcme-320-l Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.
CVE-2024-48657 1 Princelycesar 1 Hospital Management System 2026-06-17 N/A 7.2 HIGH
SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
CVE-2024-48656 1 Angeljudesuarez 1 Student Management System 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
CVE-2024-48655 1 Totaljs 1 Total.js 2026-06-17 N/A 8.8 HIGH
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
CVE-2024-48654 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component.
CVE-2024-48652 1 Tuzitio 1 Camaleon Cms 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.
CVE-2024-48651 2026-06-17 N/A 7.5 HIGH
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
CVE-2024-48648 1 Sage 1 Sage Frp 1000 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.
CVE-2024-48647 1 Sage 1 Sage Frp 1000 2026-06-17 N/A 7.2 HIGH
A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive information, including configuration files that may contain credentials and system settings, which could lead to further compromise of the server.
CVE-2024-48646 1 Sage 1 Sage Frp 1000 2026-06-17 N/A 8.1 HIGH
An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.
CVE-2024-48645 2026-06-17 N/A 7.5 HIGH
In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files used by the game when installed on a dedicated server.
CVE-2024-48644 2026-06-17 N/A 5.3 MEDIUM
Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames.