Vulnerabilities (CVE)

Total 395814 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42562 1 Krishna9772 1 Pharmacy Management System 2026-06-17 N/A 9.8 CRITICAL
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
CVE-2024-42561 1 Krishna9772 1 Pharmacy Management System 2026-06-17 N/A 8.8 HIGH
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.
CVE-2024-42560 1 Varunsardana004 1 Blood Bank And Donation Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details parameter.
CVE-2024-42559 2026-06-17 N/A 9.8 CRITICAL
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authenticate without providing a valid password.
CVE-2024-42558 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 9.8 CRITICAL
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
CVE-2024-42557 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42556 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 9.8 CRITICAL
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
CVE-2024-42555 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42554 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 8.8 HIGH
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.
CVE-2024-42553 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42552 1 Vaibhavverma9999 1 Hotel Management System 2026-06-17 N/A 8.6 HIGH
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_room_history.php.
CVE-2024-42550 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management System commit 18aa3d allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.
CVE-2024-42547 1 Totolink 2 A3100r, A3100r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
CVE-2024-42546 1 Totolink 2 A3100r, A3100r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.
CVE-2024-42545 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.
CVE-2024-42543 1 Totolink 2 A3700r, A3700r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
CVE-2024-42533 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.
CVE-2024-42523 1 Publiccms 1 Publiccms 2026-06-17 N/A 7.2 HIGH
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
CVE-2024-42520 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
CVE-2024-42516 1 Apache 1 Http Server 2026-06-17 N/A 7.5 HIGH
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.