Vulnerabilities (CVE)

Total 395651 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46410 1 Publiccms 1 Publiccms 2026-06-17 N/A 4.8 MEDIUM
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature
CVE-2024-46409 1 Seeddms 1 Seeddms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.
CVE-2024-46394 1 Frogcms Project 1 Frogcms 2026-06-17 N/A 8.8 HIGH
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
CVE-2024-46382 1 Linlinjava 1 Litemall 2026-06-17 N/A 7.5 HIGH
A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java.
CVE-2024-46377 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.
CVE-2024-46376 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.
CVE-2024-46375 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.
CVE-2024-46374 1 Mayurik 1 Best House Rental Management System 2026-06-17 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.
CVE-2024-46373 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
CVE-2024-46372 1 Dedecms 1 Dedecms 2026-06-17 N/A 6.1 MEDIUM
DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.
CVE-2024-46367 1 Webkul 1 Krayin Crm 2026-06-17 N/A 9.6 CRITICAL
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
CVE-2024-46366 1 Webkul 1 Krayin Crm 2026-06-17 N/A 8.8 HIGH
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
CVE-2024-46362 1 Frogcms Project 1 Frogcms 2026-06-17 N/A 8.8 HIGH
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
CVE-2024-46341 1 Tp-link 2 Tl-wr845n, Tl-wr845n Firmware 2026-06-17 N/A 8.0 HIGH
TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.
CVE-2024-46340 1 Tp-link 2 Tl-wr845n, Tl-wr845n Firmware 2026-06-17 N/A 9.8 CRITICAL
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.
CVE-2024-46336 1 Kashipara 1 School Management System 2026-06-17 N/A 6.1 MEDIUM
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
CVE-2024-46335 1 Phpgurukul 1 Complaint Management System 2026-06-17 N/A 4.6 MEDIUM
PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.
CVE-2024-46334 1 Kashipara 1 School Management System 2026-06-17 N/A 6.1 MEDIUM
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.
CVE-2024-46333 1 Piwigo 1 Piwigo 2026-06-17 N/A 4.8 MEDIUM
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.
CVE-2024-46331 1 Modstart 1 Mostartcms 2026-06-17 N/A 7.2 HIGH
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.