Total
395527 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48581 | 1 Mayurik | 1 Best Courier Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component. | |||||
| CVE-2024-48580 | 1 Mayurik | 1 Best Courier Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request. | |||||
| CVE-2024-48579 | 1 Mayurik | 1 Best House Rental Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request. | |||||
| CVE-2024-48573 | 1 Aquila-cms | 1 Aquilacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. | |||||
| CVE-2024-48572 | 1 Aquila-cms | 1 Aquilacms | 2026-06-17 | N/A | 5.3 MEDIUM |
| A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs due to insufficiently validated user input being processed as a regular expression, which is then matched against email addresses to find duplicate entries. | |||||
| CVE-2024-48570 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 7.5 HIGH |
| Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php. | |||||
| CVE-2024-48569 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/ | |||||
| CVE-2024-48548 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a valid serial number via a bruteforce attack. | |||||
| CVE-2024-48547 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |||||
| CVE-2024-48546 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |||||
| CVE-2024-48545 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |||||
| CVE-2024-48542 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |||||
| CVE-2024-48541 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |||||
| CVE-2024-48540 | 2026-06-17 | N/A | 6.2 MEDIUM | ||
| Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file. | |||||
| CVE-2024-48536 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request. | |||||
| CVE-2024-48535 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |||||
| CVE-2024-48534 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |||||
| CVE-2024-48533 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.3 MEDIUM |
| A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts. | |||||
| CVE-2024-48531 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |||||
| CVE-2024-48530 | 1 Esoftplanner | 1 Esoft Planner | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |||||
