Vulnerabilities (CVE)

Total 395659 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46213 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2024-46212 1 Redaxo 1 Redaxo 2026-06-17 N/A 4.9 MEDIUM
An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.
CVE-2024-46210 1 Redaxo 1 Redaxo 2026-06-17 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-46209 1 Redaxo 1 Redaxo 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
CVE-2024-46103 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
CVE-2024-46101 1 Gdidees 1 Gdidees Cms 2026-06-17 N/A 9.8 CRITICAL
GDidees CMS <= v3.9.1 has a file upload vulnerability.
CVE-2024-46097 1 Testlink 1 Testlink 2026-06-17 N/A 8.1 HIGH
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.
CVE-2024-46089 1 74cms 1 74cms 2026-06-17 N/A 6.3 MEDIUM
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
CVE-2024-46086 1 Frogcms Project 1 Frogcms 2026-06-17 N/A 8.8 HIGH
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123
CVE-2024-46085 1 Frogcms Project 1 Frogcms 2026-06-17 N/A 8.8 HIGH
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename
CVE-2024-46083 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 5.4 MEDIUM
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.
CVE-2024-46082 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 5.4 MEDIUM
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.
CVE-2024-46081 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 5.4 MEDIUM
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.
CVE-2024-46080 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 8.0 HIGH
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
CVE-2024-46079 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 6.1 MEDIUM
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
CVE-2024-46078 1 Adonesevangelista 1 Sports Management System 2026-06-17 N/A 7.5 HIGH
itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.
CVE-2024-46077 1 Mayurik 1 Online Tours And Travels Management System 2026-06-17 N/A 5.4 MEDIUM
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.
CVE-2024-46076 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 9.8 CRITICAL
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
CVE-2024-46073 2026-06-17 N/A 6.1 MEDIUM
A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.
CVE-2024-46062 2 Apple, Conda 2 Macos, Miniconda3 2026-06-17 N/A 7.8 HIGH
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.