Total
395535 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48218 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. | |||||
| CVE-2024-48217 | 2026-06-17 | N/A | 8.8 HIGH | ||
| An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation. | |||||
| CVE-2024-48214 | 2026-06-17 | N/A | 8.4 HIGH | ||
| KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera. | |||||
| CVE-2024-48213 | 1 Rockoa | 1 Xinhu | 2026-06-17 | N/A | 4.3 MEDIUM |
| RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php. | |||||
| CVE-2024-48208 | 1 Pureftpd | 1 Pure-ftpd | 2026-06-17 | N/A | 8.6 HIGH |
| pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file. | |||||
| CVE-2024-48206 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code. | |||||
| CVE-2024-48204 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script. | |||||
| CVE-2024-48202 | 1 Thecosy | 1 Icecms | 2026-06-17 | N/A | 9.8 CRITICAL |
| icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. | |||||
| CVE-2024-48200 | 2026-06-17 | N/A | 8.4 HIGH | ||
| An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe) | |||||
| CVE-2024-48196 | 1 Eyoucms | 1 Eyoucms | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. | |||||
| CVE-2024-48195 | 1 Eyoucms | 1 Eyoucms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. | |||||
| CVE-2024-48192 | 1 Tenda | 2 G3, G3 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root | |||||
| CVE-2024-48191 | 1 Timgreen | 1 Dingfanzu Cms | 2026-06-17 | N/A | 6.3 MEDIUM |
| dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17 | |||||
| CVE-2024-48180 | 1 Classcms | 1 Classcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code. | |||||
| CVE-2024-48178 | 1 Newbee-mall Project | 1 Newbee-mall | 2026-06-17 | N/A | 8.1 HIGH |
| newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter. | |||||
| CVE-2024-48177 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 8.8 HIGH |
| MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do. | |||||
| CVE-2024-48176 | 1 Lylme | 1 Lylme Spage | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend. | |||||
| CVE-2024-48170 | 1 Phpgurukul | 1 Small Crm | 2026-06-17 | N/A | 5.4 MEDIUM |
| PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php. | |||||
| CVE-2024-48168 | 1 Dlink | 2 Dcs-960l, Dcs-960l Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code. | |||||
| CVE-2024-48153 | 1 Draytek | 2 Vigor3900, Vigor3900 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function. | |||||
