Total
395659 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-46213 | 1 Redaxo | 1 Redaxo | 2026-06-17 | N/A | 7.2 HIGH |
| REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability. | |||||
| CVE-2024-46212 | 1 Redaxo | 1 Redaxo | 2026-06-17 | N/A | 4.9 MEDIUM |
| An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal. | |||||
| CVE-2024-46210 | 1 Redaxo | 1 Redaxo | 2026-06-17 | N/A | 7.2 HIGH |
| An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-46209 | 1 Redaxo | 1 Redaxo | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter. | |||||
| CVE-2024-46103 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. | |||||
| CVE-2024-46101 | 1 Gdidees | 1 Gdidees Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| GDidees CMS <= v3.9.1 has a file upload vulnerability. | |||||
| CVE-2024-46097 | 1 Testlink | 1 Testlink | 2026-06-17 | N/A | 8.1 HIGH |
| TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges. | |||||
| CVE-2024-46089 | 1 74cms | 1 74cms | 2026-06-17 | N/A | 6.3 MEDIUM |
| 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin. | |||||
| CVE-2024-46086 | 1 Frogcms Project | 1 Frogcms | 2026-06-17 | N/A | 8.8 HIGH |
| FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123 | |||||
| CVE-2024-46085 | 1 Frogcms Project | 1 Frogcms | 2026-06-17 | N/A | 8.8 HIGH |
| FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename | |||||
| CVE-2024-46083 | 1 Scriptcase | 1 Scriptcase | 2026-06-17 | N/A | 5.4 MEDIUM |
| Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users. | |||||
| CVE-2024-46082 | 1 Scriptcase | 1 Scriptcase | 2026-06-17 | N/A | 5.4 MEDIUM |
| Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters. | |||||
| CVE-2024-46081 | 1 Scriptcase | 1 Scriptcase | 2026-06-17 | N/A | 5.4 MEDIUM |
| Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform. | |||||
| CVE-2024-46080 | 1 Scriptcase | 1 Scriptcase | 2026-06-17 | N/A | 8.0 HIGH |
| Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function. | |||||
| CVE-2024-46079 | 1 Scriptcase | 1 Scriptcase | 2026-06-17 | N/A | 6.1 MEDIUM |
| Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter. | |||||
| CVE-2024-46078 | 1 Adonesevangelista | 1 Sports Management System | 2026-06-17 | N/A | 7.5 HIGH |
| itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id. | |||||
| CVE-2024-46077 | 1 Mayurik | 1 Online Tours And Travels Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php. | |||||
| CVE-2024-46076 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 9.8 CRITICAL |
| RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code. | |||||
| CVE-2024-46073 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place. | |||||
| CVE-2024-46062 | 2 Apple, Conda | 2 Macos, Miniconda3 | 2026-06-17 | N/A | 7.8 HIGH |
| Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user. | |||||
