Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25428 1 Mrcms 1 Mrcms 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
CVE-2024-25422 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
CVE-2024-25421 1 Igniterealtime 1 Openfire 2026-06-17 N/A 9.8 CRITICAL
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
CVE-2024-25420 1 Igniterealtime 1 Openfire 2026-06-17 N/A 7.2 HIGH
An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
CVE-2024-25419 1 Flusity 1 Flusity 2026-06-17 N/A 8.8 HIGH
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.
CVE-2024-25418 1 Flusity 1 Flusity 2026-06-17 N/A 8.8 HIGH
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.
CVE-2024-25417 1 Flusity 1 Flusity 2026-06-17 N/A 8.8 HIGH
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.
CVE-2024-25415 1 Phoenixcart 1 Ce Phoenix Cart 2026-06-17 N/A 7.2 HIGH
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.
CVE-2024-25414 1 Cszcms 1 Csz Cms 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVE-2024-25413 1 Firebearstudio 1 Improved Import \& Export 2026-06-17 N/A 7.2 HIGH
A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.
CVE-2024-25412 1 Flatpress 1 Flatpress 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.
CVE-2024-25411 1 Flatpress 1 Flatpress 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.
CVE-2024-25410 1 Flusity 1 Flusity 2026-06-17 N/A 6.5 MEDIUM
flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.
CVE-2024-25407 1 Steve-community 1 Steve 2026-06-17 N/A 7.5 HIGH
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.
CVE-2024-25400 1 Intelliants 1 Subrion 2026-06-17 N/A 9.8 CRITICAL
Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly vulnerable method is not present in the file.
CVE-2024-25399 1 Intelliants 1 Subrion Cms 2026-06-17 N/A 6.1 MEDIUM
Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
CVE-2024-25398 1 Srelay Project 1 Srelay 2026-06-17 N/A 7.5 HIGH
In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.
CVE-2024-25395 1 Rt-thread 1 Rt-thread 2026-06-17 N/A 8.8 HIGH
A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2.
CVE-2024-25394 1 Rt-thread 1 Rt-thread 2026-06-17 N/A 4.3 MEDIUM
A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.
CVE-2024-25393 1 Rt-thread 1 Rt-thread 2026-06-17 N/A 9.8 CRITICAL
A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.