CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-31615CRITICAL | ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. CWE-434Apr 25, 2024 | CVSS9.8v3.1 | EPSS0.712% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-20601CRITICAL | thinkcmf thinkcmf Improper Control of Generation of Code ('Code Injection')An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. | CVSS9.8v3.1 | EPSS7.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-7580HIGH | thinkcmf thinkcmf Improper Control of Generation of Code ('Code Injection')ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection. CWE-94Feb 7, 2019 | CVSS8.8v3.0 | EPSS9.93% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |