Vulnerabilities (CVE)

Total 395652 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46261 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
CVE-2024-46259 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
CVE-2024-46258 1 Randygaul 1 Cute Png 2026-06-17 N/A 7.8 HIGH
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
CVE-2024-46257 1 Jc21 1 Nginx Proxy Manager 2026-06-17 N/A 6.3 MEDIUM
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
CVE-2024-46256 1 Jc21 1 Nginx Proxy Manager 2026-06-17 N/A 9.8 CRITICAL
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
CVE-2024-46241 1 Phpgurukul 1 Dairy Farm Shop Management System 2026-06-17 N/A 5.9 MEDIUM
PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.
CVE-2024-46240 1 O-dyn 1 Collabtive 2026-06-17 N/A 4.8 MEDIUM
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.
CVE-2024-46239 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.9 MEDIUM
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
CVE-2024-46238 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.9 MEDIUM
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
CVE-2024-46237 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
CVE-2024-46236 1 Codeastro 1 Membership Management System 2026-06-17 N/A 5.4 MEDIUM
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
CVE-2024-46226 1 Helpdeskz 1 Helpdeskz 2026-06-17 N/A 4.8 MEDIUM
A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.
CVE-2024-46215 2026-06-17 N/A 6.5 MEDIUM
A vulnerability was discovered in KM08-708H-v1.1, There is a buffer overflow in the sub_445BDC() function within the /usr/sbin/goahead program; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.
CVE-2024-46213 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2024-46212 1 Redaxo 1 Redaxo 2026-06-17 N/A 4.9 MEDIUM
An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.
CVE-2024-46210 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-46209 1 Redaxo 1 Redaxo 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
CVE-2024-46103 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
CVE-2024-46101 1 Gdidees 1 Gdidees Cms 2026-06-17 N/A 9.8 CRITICAL
GDidees CMS <= v3.9.1 has a file upload vulnerability.
CVE-2024-46097 1 Testlink 1 Testlink 2026-06-17 N/A 8.1 HIGH
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.