Vulnerabilities (CVE)

Total 396407 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37872 1 Angeljudesuarez 1 Billing System 2026-06-17 N/A 8.1 HIGH
SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2024-37871 1 Emiloi 1 Online Discussion Forum 2026-06-17 N/A 8.2 HIGH
SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter.
CVE-2024-37870 1 Itsourcecode 1 Learning Management System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.
CVE-2024-37869 1 Emiloimagtolis 1 Online Discussion Forum 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable
CVE-2024-37868 1 Emiloimagtolis 1 Online Discussion Forum 2026-06-17 N/A 8.8 HIGH
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable.
CVE-2024-37865 1 S3browser 1 S3 Browser 2026-06-17 N/A 5.9 MEDIUM
An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.
CVE-2024-37863 2026-06-17 N/A 9.8 CRITICAL
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.
CVE-2024-37862 2026-06-17 N/A 7.3 HIGH
Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.
CVE-2024-37861 2026-06-17 N/A 9.8 CRITICAL
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.
CVE-2024-37860 2026-06-17 N/A 7.3 HIGH
Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process
CVE-2024-37855 2026-06-17 N/A 8.4 HIGH
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's Telnet port 2345 without requiring authentication credentials.
CVE-2024-37849 1 Itsourcecode 1 Billing System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.
CVE-2024-37848 1 Angeljudesuarez 1 Online Book Store Project 2026-06-17 N/A 8.4 HIGH
SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.
CVE-2024-37847 1 Radixiot 2 Mango, Mangoapi 2026-06-17 N/A 8.8 HIGH
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.
CVE-2024-37846 1 Radixiot 1 Mango 2026-06-17 N/A 4.6 MEDIUM
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
CVE-2024-37845 1 Radixiot 1 Mango 2026-06-17 N/A 7.2 HIGH
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
CVE-2024-37844 1 Radixiot 1 Mango 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-37843 1 Craftcms 1 Craft Cms 2026-06-17 N/A 9.8 CRITICAL
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CVE-2024-37840 1 Itsourcecode 1 Learning Management System 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
CVE-2024-37831 1 Itsourcecode 1 Payroll Management System 2026-06-17 N/A 9.8 CRITICAL
Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.