Total
395527 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48707 | 1 O-dyn | 1 Collabtive | 2026-06-17 | N/A | 5.4 MEDIUM |
| Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file. | |||||
| CVE-2024-48706 | 1 O-dyn | 1 Collabtive | 2026-06-17 | N/A | 5.4 MEDIUM |
| Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively. | |||||
| CVE-2024-48704 | 1 Phpgurukul | 1 Medical Card Generation System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes. | |||||
| CVE-2024-48703 | 1 Anujk305 | 1 Medical Card Generation System | 2026-06-17 | N/A | 4.8 MEDIUM |
| PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter. | |||||
| CVE-2024-48702 | 1 Phpgurukul | 1 Old Age Home Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter. | |||||
| CVE-2024-48700 | 1 Kliqqi | 1 Kliqqi Cms | 2026-06-17 | N/A | 7.2 HIGH |
| Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component. | |||||
| CVE-2024-48694 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component. | |||||
| CVE-2024-48662 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component. | |||||
| CVE-2024-48659 | 1 Dcnetworks | 2 Dcme-320-l, Dcme-320-l Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component. | |||||
| CVE-2024-48657 | 1 Princelycesar | 1 Hospital Management System | 2026-06-17 | N/A | 7.2 HIGH |
| SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code. | |||||
| CVE-2024-48656 | 1 Angeljudesuarez | 1 Student Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code. | |||||
| CVE-2024-48655 | 1 Totaljs | 1 Total.js | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. | |||||
| CVE-2024-48654 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted script to the login.php component. | |||||
| CVE-2024-48652 | 1 Tuzitio | 1 Camaleon Cms | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field. | |||||
| CVE-2024-48651 | 2026-06-17 | N/A | 7.5 HIGH | ||
| In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql. | |||||
| CVE-2024-48648 | 1 Sage | 1 Sage Frp 1000 | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding. | |||||
| CVE-2024-48647 | 1 Sage | 1 Sage Frp 1000 | 2026-06-17 | N/A | 7.2 HIGH |
| A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive information, including configuration files that may contain credentials and system settings, which could lead to further compromise of the server. | |||||
| CVE-2024-48646 | 1 Sage | 1 Sage Frp 1000 | 2026-06-17 | N/A | 8.1 HIGH |
| An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise. | |||||
| CVE-2024-48645 | 2026-06-17 | N/A | 7.5 HIGH | ||
| In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files used by the game when installed on a dedicated server. | |||||
| CVE-2024-48644 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames. | |||||
