Total
395535 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48246 | 1 Janobe | 1 Vehicle Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php. | |||||
| CVE-2024-48241 | 1 Radare | 1 Radare2 | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. | |||||
| CVE-2024-48239 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS). | |||||
| CVE-2024-48238 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 4.7 MEDIUM |
| WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter. | |||||
| CVE-2024-48237 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php. | |||||
| CVE-2024-48236 | 1 Ofcms Project | 1 Ofcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file | |||||
| CVE-2024-48235 | 1 Ofcms Project | 1 Ofcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. | |||||
| CVE-2024-48234 | 2026-06-17 | N/A | 4.9 MEDIUM | ||
| An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in Server-side request forgery (SSRF) vulnerability that can read server files. | |||||
| CVE-2024-48233 | 1 Mipjz Project | 1 Mipjz | 2026-06-17 | N/A | 4.8 MEDIUM |
| mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter. | |||||
| CVE-2024-48232 | 1 Mipjz Project | 1 Mipjz | 2026-06-17 | N/A | 4.9 MEDIUM |
| An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files. | |||||
| CVE-2024-48231 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. | |||||
| CVE-2024-48230 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | |||||
| CVE-2024-48229 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | |||||
| CVE-2024-48228 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 6.1 MEDIUM |
| An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS). | |||||
| CVE-2024-48227 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 4.9 MEDIUM |
| Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS). | |||||
| CVE-2024-48226 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | |||||
| CVE-2024-48225 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 6.5 MEDIUM |
| Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. | |||||
| CVE-2024-48224 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 4.9 MEDIUM |
| Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile. | |||||
| CVE-2024-48223 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | |||||
| CVE-2024-48222 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | |||||
