Vulnerabilities (CVE)

Total 395696 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-44724 1 Autocms Project 1 Autocms 2026-06-17 N/A 7.2 HIGH
AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.
CVE-2024-44722 1 Anolis 1 Sysak 2026-06-17 N/A 9.8 CRITICAL
SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
CVE-2024-44721 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
CVE-2024-44720 1 Seacms 1 Seacms 2026-06-17 N/A 7.5 HIGH
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
CVE-2024-44717 1 Dedebiz 1 Dedebiz 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-44716 1 Dedebiz 1 Dedebiz 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-44685 2026-06-17 N/A 5.0 MEDIUM
Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.
CVE-2024-44684 1 Tpmecms 1 Tpmecms 2026-06-17 N/A 6.1 MEDIUM
TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.
CVE-2024-44683 1 Seacms 1 Seacms 2026-06-17 N/A 6.1 MEDIUM
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
CVE-2024-44682 1 Shopxo 1 Shopxo 2026-06-17 N/A 6.1 MEDIUM
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
CVE-2024-44678 2026-06-17 N/A 8.0 HIGH
Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.
CVE-2024-44677 1 Eladmin 1 Eladmin 2026-06-17 N/A 9.8 CRITICAL
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVE-2024-44676 1 Eladmin 1 Eladmin 2026-06-17 N/A 4.8 MEDIUM
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreController. java.
CVE-2024-44674 1 Dlink 2 Covr-2600r, Covr-2600r Firmware 2026-06-17 N/A 5.7 MEDIUM
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.
CVE-2024-44664 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
CVE-2024-44663 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
CVE-2024-44662 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
CVE-2024-44661 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
CVE-2024-44660 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
CVE-2024-44659 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 9.8 CRITICAL
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.