Total
395528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48343 | 1 Esafenet | 1 Cdg | 2026-06-17 | N/A | 6.3 MEDIUM |
| A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page. | |||||
| CVE-2024-48341 | 1 Geeeeeeeek | 1 Dingfanzu | 2026-06-17 | N/A | 3.7 LOW |
| dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop | |||||
| CVE-2024-48336 | 2026-06-17 | N/A | 8.4 HIGH | ||
| The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local untrusted app with no additional privileges to silently execute arbitrary code in the Magisk app and escalate privileges to root via a crafted package, aka Bug #8279. User interaction is not needed for exploitation. | |||||
| CVE-2024-48325 | 1 Portabilis | 1 I-educar | 2026-06-17 | N/A | 8.1 HIGH |
| Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, allowing an unauthenticated remote attacker to inject malicious SQL commands. | |||||
| CVE-2024-48322 | 2026-06-17 | N/A | 8.1 HIGH | ||
| UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability. | |||||
| CVE-2024-48312 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page. | |||||
| CVE-2024-48311 | 1 Piwigo | 1 Piwigo | 2026-06-17 | N/A | 8.8 HIGH |
| Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. | |||||
| CVE-2024-48310 | 2026-06-17 | N/A | 7.5 HIGH | ||
| AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access the backend API or other sensitive information. | |||||
| CVE-2024-48307 | 1 Jeecg | 1 Jeecg Boot | 2026-06-17 | N/A | 9.8 CRITICAL |
| JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | |||||
| CVE-2024-48294 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |||||
| CVE-2024-48293 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings. | |||||
| CVE-2024-48292 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges. | |||||
| CVE-2024-48291 | 1 Timgreen | 1 Dingfanzu Cms | 2026-06-17 | N/A | 6.3 MEDIUM |
| dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17 | |||||
| CVE-2024-48289 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| An issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via supplying a crafted LL_PAUSE_ENC_REQ packet. | |||||
| CVE-2024-48288 | 1 Tp-link | 2 Tl-ipc42c, Tl-ipc42c Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend. | |||||
| CVE-2024-48286 | 1 Linksys | 2 E3000, E3000 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. | |||||
| CVE-2024-48284 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary scripts via the searchkey parameter in a POST HTTP request. | |||||
| CVE-2024-48283 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter. | |||||
| CVE-2024-48282 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 7.6 HIGH |
| A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request. | |||||
| CVE-2024-48280 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 7.6 HIGH |
| A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request. | |||||
