Total
395957 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-40550 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40549 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40548 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40547 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 6.5 MEDIUM |
| PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace. | |||||
| CVE-2024-40546 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40545 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2024-40544 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit. | |||||
| CVE-2024-40543 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 8.8 HIGH |
| PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage. | |||||
| CVE-2024-40542 | 1 Codermy | 1 My-springsecurity-plus | 2026-06-17 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/role?offset. | |||||
| CVE-2024-40541 | 1 Codermy | 1 My-springsecurity-plus | 2026-06-17 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build. | |||||
| CVE-2024-40540 | 1 Codermy | 1 My-springsecurity-plus | 2026-06-17 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept. | |||||
| CVE-2024-40539 | 1 Codermy | 1 My-springsecurity-plus | 2026-06-17 | N/A | 9.8 CRITICAL |
| my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/user. | |||||
| CVE-2024-40536 | 1 Szlbt | 2 Lbt-t300-t400, Lbt-t300-t400 Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the config_3g_para function. | |||||
| CVE-2024-40535 | 1 Szlbt | 2 Lbt-t300-t400, Lbt-t300-t400 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function. | |||||
| CVE-2024-40531 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by injecting additional parameters via profile management functions. | |||||
| CVE-2024-40530 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header. | |||||
| CVE-2024-40524 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component. | |||||
| CVE-2024-40522 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 8.8 HIGH |
| There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in without filtering them before writing them into the php file. An authenticated attacker can exploit this vulnerability to execute arbitrary commands and obtain system permissions. | |||||
| CVE-2024-40521 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 8.8 HIGH |
| SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrictions on the edited file, attackers can still bypass the restrictions and write code in some way, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges. | |||||
| CVE-2024-40520 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 8.8 HIGH |
| SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly splicing and writing the user input data into inc_photowatermark_config.php without processing it, which allows authenticated attackers to exploit the vulnerability to execute arbitrary commands and obtain system permissions. | |||||
