Total
395651 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-46410 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 4.8 MEDIUM |
| PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature | |||||
| CVE-2024-46409 | 1 Seeddms | 1 Seeddms | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page. | |||||
| CVE-2024-46394 | 1 Frogcms Project | 1 Frogcms | 2026-06-17 | N/A | 8.8 HIGH |
| FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add | |||||
| CVE-2024-46382 | 1 Linlinjava | 1 Litemall | 2026-06-17 | N/A | 7.5 HIGH |
| A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java. | |||||
| CVE-2024-46377 | 1 Mayurik | 1 Best House Rental Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php. | |||||
| CVE-2024-46376 | 1 Mayurik | 1 Best House Rental Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php. | |||||
| CVE-2024-46375 | 1 Mayurik | 1 Best House Rental Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php. | |||||
| CVE-2024-46374 | 1 Mayurik | 1 Best House Rental Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php. | |||||
| CVE-2024-46373 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 8.8 HIGH |
| Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. | |||||
| CVE-2024-46372 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 6.1 MEDIUM |
| DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module. | |||||
| CVE-2024-46367 | 1 Webkul | 1 Krayin Crm | 2026-06-17 | N/A | 9.6 CRITICAL |
| A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. | |||||
| CVE-2024-46366 | 1 Webkul | 1 Krayin Crm | 2026-06-17 | N/A | 8.8 HIGH |
| A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. | |||||
| CVE-2024-46362 | 1 Frogcms Project | 1 Frogcms | 2026-06-17 | N/A | 8.8 HIGH |
| FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory | |||||
| CVE-2024-46341 | 1 Tp-link | 2 Tl-wr845n, Tl-wr845n Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack. | |||||
| CVE-2024-46340 | 1 Tp-link | 2 Tl-wr845n, Tl-wr845n Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset. | |||||
| CVE-2024-46336 | 1 Kashipara | 1 School Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php. | |||||
| CVE-2024-46335 | 1 Phpgurukul | 1 Complaint Management System | 2026-06-17 | N/A | 4.6 MEDIUM |
| PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php. | |||||
| CVE-2024-46334 | 1 Kashipara | 1 School Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php. | |||||
| CVE-2024-46333 | 1 Piwigo | 1 Piwigo | 2026-06-17 | N/A | 4.8 MEDIUM |
| An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function. | |||||
| CVE-2024-46331 | 1 Modstart | 1 Mostartcms | 2026-06-17 | N/A | 7.2 HIGH |
| ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL. | |||||
