Vulnerabilities (CVE)

Total 395535 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48218 1 Funadmin 1 Funadmin 2026-06-17 N/A 7.2 HIGH
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
CVE-2024-48217 2026-06-17 N/A 8.8 HIGH
An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.
CVE-2024-48214 2026-06-17 N/A 8.4 HIGH
KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.
CVE-2024-48213 1 Rockoa 1 Xinhu 2026-06-17 N/A 4.3 MEDIUM
RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php.
CVE-2024-48208 1 Pureftpd 1 Pure-ftpd 2026-06-17 N/A 8.6 HIGH
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
CVE-2024-48206 2026-06-17 N/A 9.8 CRITICAL
A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.
CVE-2024-48204 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2024-48202 1 Thecosy 1 Icecms 2026-06-17 N/A 9.8 CRITICAL
icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
CVE-2024-48200 2026-06-17 N/A 8.4 HIGH
An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is spawning one Administrative cmd (conhost.exe)
CVE-2024-48196 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 7.5 HIGH
An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
CVE-2024-48195 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter.
CVE-2024-48192 1 Tenda 2 G3, G3 Firmware 2026-06-17 N/A 8.0 HIGH
Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root
CVE-2024-48191 1 Timgreen 1 Dingfanzu Cms 2026-06-17 N/A 6.3 MEDIUM
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17
CVE-2024-48180 1 Classcms 1 Classcms 2026-06-17 N/A 9.8 CRITICAL
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.
CVE-2024-48178 1 Newbee-mall Project 1 Newbee-mall 2026-06-17 N/A 8.1 HIGH
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
CVE-2024-48177 1 Mrcms 1 Mrcms 2026-06-17 N/A 8.8 HIGH
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
CVE-2024-48176 1 Lylme 1 Lylme Spage 2026-06-17 N/A 9.8 CRITICAL
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.
CVE-2024-48170 1 Phpgurukul 1 Small Crm 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.
CVE-2024-48168 1 Dlink 2 Dcs-960l, Dcs-960l Firmware 2026-06-17 N/A 9.8 CRITICAL
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.
CVE-2024-48153 1 Draytek 2 Vigor3900, Vigor3900 Firmware 2026-06-17 N/A 9.8 CRITICAL
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.