Vulnerabilities (CVE)

Total 395528 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48279 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 7.6 HIGH
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.
CVE-2024-48278 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 5.5 MEDIUM
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.
CVE-2024-48272 1 Dlink 2 Dsl-6740c, Dsl-6740c Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.
CVE-2024-48271 1 Dlink 2 Dsl-6740c, Dsl-6740c Firmware 2026-06-17 N/A 8.8 HIGH
D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.
CVE-2024-48270 1 Misstt123 1 Oasys 2026-06-17 N/A 7.5 HIGH
An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.
CVE-2024-48259 1 Magicbug 1 Cloudlog 2026-06-17 N/A 7.3 HIGH
Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.
CVE-2024-48257 1 Wavelog 1 Wavelog 2026-06-17 N/A 9.8 CRITICAL
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
CVE-2024-48255 1 Magicbug 1 Cloudlog 2026-06-17 N/A 9.8 CRITICAL
Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
CVE-2024-48253 1 Magicbug 1 Cloudlog 2026-06-17 N/A 9.8 CRITICAL
Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
CVE-2024-48251 1 Wavelog 1 Wavelog 2026-06-17 N/A 9.8 CRITICAL
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48249 1 Wavelog 1 Wavelog 2026-06-17 N/A 7.3 HIGH
Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48248 1 Nakivo 1 Backup \& Replication Director 2026-06-17 N/A 8.6 HIGH
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
CVE-2024-48246 1 Janobe 1 Vehicle Management System 2026-06-17 N/A 5.4 MEDIUM
Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.
CVE-2024-48241 1 Radare 1 Radare2 2026-06-17 N/A 5.5 MEDIUM
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.
CVE-2024-48239 1 Wtcms Project 1 Wtcms 2026-06-17 N/A 4.8 MEDIUM
An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
CVE-2024-48238 1 Wtcms Project 1 Wtcms 2026-06-17 N/A 4.7 MEDIUM
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
CVE-2024-48237 1 Wtcms Project 1 Wtcms 2026-06-17 N/A 9.8 CRITICAL
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
CVE-2024-48236 1 Ofcms Project 1 Ofcms 2026-06-17 N/A 6.5 MEDIUM
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
CVE-2024-48235 1 Ofcms Project 1 Ofcms 2026-06-17 N/A 6.5 MEDIUM
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
CVE-2024-48234 2026-06-17 N/A 4.9 MEDIUM
An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in Server-side request forgery (SSRF) vulnerability that can read server files.