Vulnerabilities (CVE)

Total 395696 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-44798 1 Anujk305 1 Bus Pass Management System 2026-06-17 N/A 4.8 MEDIUM
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.
CVE-2024-44786 2026-06-17 N/A 7.5 HIGH
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.
CVE-2024-44775 1 Davidepianca98 1 Kmqtt 2026-06-17 N/A 7.5 HIGH
kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by sending a specially crafted MQTT CONNECT packet that triggers an unhandled null reference, leading to an immediate process termination.
CVE-2024-44771 2026-06-17 N/A 6.1 MEDIUM
BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template function.
CVE-2024-44762 1 Webmin 1 Usermin 2026-06-17 N/A 5.3 MEDIUM
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
CVE-2024-44761 1 Gzequan 1 Eq Enterprise Management System 2026-06-17 N/A 9.8 CRITICAL
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
CVE-2024-44760 1 Sunmochina 1 Enterprise Management System 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.
CVE-2024-44759 1 Nuserp 1 Nus-m9 Erp 2026-06-17 N/A 7.5 HIGH
An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.
CVE-2024-44758 1 Nuserp 1 Nus-m9 Erp 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.
CVE-2024-44757 1 Nuserp 1 Nus-m9 Erp 2026-06-17 N/A 7.5 HIGH
An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.
CVE-2024-44756 1 Nuserp 1 Nus-m9 Erp 2026-06-17 N/A 9.8 CRITICAL
NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.
CVE-2024-44744 2026-06-17 N/A 5.7 MEDIUM
An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin users.
CVE-2024-44739 1 Oretnom23 1 Simple Forum Website 2026-06-17 N/A 8.8 HIGH
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-44734 2026-06-17 N/A 7.5 HIGH
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.
CVE-2024-44731 2026-06-17 N/A 4.7 MEDIUM
Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections.
CVE-2024-44730 2026-06-17 N/A 9.1 CRITICAL
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.
CVE-2024-44729 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
CVE-2024-44728 1 Angeljudesuarez 1 Event Management System 2026-06-17 N/A 6.1 MEDIUM
Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.
CVE-2024-44727 1 Angeljudesuarez 1 Event Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
CVE-2024-44725 1 Autocms Project 1 Autocms 2026-06-17 N/A 7.2 HIGH
AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.