Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25428 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter. | |||||
| CVE-2024-25422 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component. | |||||
| CVE-2024-25421 | 1 Igniterealtime | 1 Openfire | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component. | |||||
| CVE-2024-25420 | 1 Igniterealtime | 1 Openfire | 2026-06-17 | N/A | 7.2 HIGH |
| An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component. | |||||
| CVE-2024-25419 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 8.8 HIGH |
| flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php. | |||||
| CVE-2024-25418 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 8.8 HIGH |
| flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php. | |||||
| CVE-2024-25417 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 8.8 HIGH |
| flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php. | |||||
| CVE-2024-25415 | 1 Phoenixcart | 1 Ce Phoenix Cart | 2026-06-17 | N/A | 7.2 HIGH |
| A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php. | |||||
| CVE-2024-25414 | 1 Cszcms | 1 Csz Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file. | |||||
| CVE-2024-25413 | 1 Firebearstudio | 1 Improved Import \& Export | 2026-06-17 | N/A | 7.2 HIGH |
| A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file. | |||||
| CVE-2024-25412 | 1 Flatpress | 1 Flatpress | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field. | |||||
| CVE-2024-25411 | 1 Flatpress | 1 Flatpress | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php. | |||||
| CVE-2024-25410 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 6.5 MEDIUM |
| flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php. | |||||
| CVE-2024-25407 | 1 Steve-community | 1 Steve | 2026-06-17 | N/A | 7.5 HIGH |
| SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions. | |||||
| CVE-2024-25400 | 1 Intelliants | 1 Subrion | 2026-06-17 | N/A | 9.8 CRITICAL |
| Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly vulnerable method is not present in the file. | |||||
| CVE-2024-25399 | 1 Intelliants | 1 Subrion Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php. | |||||
| CVE-2024-25398 | 1 Srelay Project | 1 Srelay | 2026-06-17 | N/A | 7.5 HIGH |
| In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service. | |||||
| CVE-2024-25395 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 8.8 HIGH |
| A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2. | |||||
| CVE-2024-25394 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 4.3 MEDIUM |
| A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character. | |||||
| CVE-2024-25393 | 1 Rt-thread | 1 Rt-thread | 2026-06-17 | N/A | 9.8 CRITICAL |
| A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2. | |||||
