Total
395528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48279 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 7.6 HIGH |
| A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request. | |||||
| CVE-2024-48278 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 5.5 MEDIUM |
| Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. | |||||
| CVE-2024-48272 | 1 Dlink | 2 Dsl-6740c, Dsl-6740c Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack. | |||||
| CVE-2024-48271 | 1 Dlink | 2 Dsl-6740c, Dsl-6740c Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack. | |||||
| CVE-2024-48270 | 1 Misstt123 | 1 Oasys | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack. | |||||
| CVE-2024-48259 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 7.3 HIGH |
| Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. | |||||
| CVE-2024-48257 | 1 Wavelog | 1 Wavelog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin. | |||||
| CVE-2024-48255 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. | |||||
| CVE-2024-48253 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. | |||||
| CVE-2024-48251 | 1 Wavelog | 1 Wavelog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. | |||||
| CVE-2024-48249 | 1 Wavelog | 1 Wavelog | 2026-06-17 | N/A | 7.3 HIGH |
| Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. | |||||
| CVE-2024-48248 | 1 Nakivo | 1 Backup \& Replication Director | 2026-06-17 | N/A | 8.6 HIGH |
| NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials). | |||||
| CVE-2024-48246 | 1 Janobe | 1 Vehicle Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php. | |||||
| CVE-2024-48241 | 1 Radare | 1 Radare2 | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. | |||||
| CVE-2024-48239 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS). | |||||
| CVE-2024-48238 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 4.7 MEDIUM |
| WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter. | |||||
| CVE-2024-48237 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php. | |||||
| CVE-2024-48236 | 1 Ofcms Project | 1 Ofcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file | |||||
| CVE-2024-48235 | 1 Ofcms Project | 1 Ofcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. | |||||
| CVE-2024-48234 | 2026-06-17 | N/A | 4.9 MEDIUM | ||
| An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in Server-side request forgery (SSRF) vulnerability that can read server files. | |||||
