Vulnerabilities (CVE)

Total 396425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36647 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.
CVE-2024-36626 1 Prestashop 1 Prestashop 2026-06-17 N/A 5.3 MEDIUM
In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.
CVE-2024-36625 1 Zulip 1 Zulip 2026-06-17 N/A 5.4 MEDIUM
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
CVE-2024-36624 1 Zulip 1 Zulip 2026-06-17 N/A 5.4 MEDIUM
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.
CVE-2024-36623 1 Mobyproject 1 Moby 2026-06-17 N/A 8.1 HIGH
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
CVE-2024-36622 1 Raspap 1 Raspap-webgui 2026-06-17 N/A 9.8 CRITICAL
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.
CVE-2024-36621 1 Mobyproject 1 Moby 2026-06-17 N/A 6.5 MEDIUM
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
CVE-2024-36620 1 Mobyproject 1 Moby 2026-06-17 N/A 6.5 MEDIUM
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-36619 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 5.3 MEDIUM
FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
CVE-2024-36618 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.2 MEDIUM
FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.
CVE-2024-36617 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.2 MEDIUM
FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.
CVE-2024-36616 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.5 MEDIUM
An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.
CVE-2024-36615 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 5.9 MEDIUM
FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.
CVE-2024-36613 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.2 MEDIUM
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
CVE-2024-36612 1 Zulip 1 Zulip Server 2026-06-17 N/A 7.5 HIGH
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
CVE-2024-36611 2026-06-17 N/A 7.5 HIGH
In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.
CVE-2024-36604 1 Tenda 2 O3, O3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
CVE-2024-36600 1 Gnu 1 Libcdio 2026-06-17 N/A 8.4 HIGH
Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
CVE-2024-36599 1 Aegon 1 Life Insurance Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.
CVE-2024-36598 2026-06-17 N/A 8.1 HIGH
An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.