Total
396425 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-36647 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page. | |||||
| CVE-2024-36626 | 1 Prestashop | 1 Prestashop | 2026-06-17 | N/A | 5.3 MEDIUM |
| In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. | |||||
| CVE-2024-36625 | 1 Zulip | 1 Zulip | 2026-06-17 | N/A | 5.4 MEDIUM |
| Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts. | |||||
| CVE-2024-36624 | 1 Zulip | 1 Zulip | 2026-06-17 | N/A | 5.4 MEDIUM |
| Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js. | |||||
| CVE-2024-36623 | 1 Mobyproject | 1 Moby | 2026-06-17 | N/A | 8.1 HIGH |
| moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes. | |||||
| CVE-2024-36622 | 1 Raspap | 1 Raspap-webgui | 2026-06-17 | N/A | 9.8 CRITICAL |
| In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter. | |||||
| CVE-2024-36621 | 1 Mobyproject | 1 Moby | 2026-06-17 | N/A | 6.5 MEDIUM |
| moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion. | |||||
| CVE-2024-36620 | 1 Mobyproject | 1 Moby | 2026-06-17 | N/A | 6.5 MEDIUM |
| moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go. | |||||
| CVE-2024-36619 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 5.3 MEDIUM |
| FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition. | |||||
| CVE-2024-36618 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 6.2 MEDIUM |
| FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition. | |||||
| CVE-2024-36617 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 6.2 MEDIUM |
| FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. | |||||
| CVE-2024-36616 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 6.5 MEDIUM |
| An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file. | |||||
| CVE-2024-36615 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 5.9 MEDIUM |
| FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread. | |||||
| CVE-2024-36613 | 1 Ffmpeg | 1 Ffmpeg | 2026-06-17 | N/A | 6.2 MEDIUM |
| FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior. | |||||
| CVE-2024-36612 | 1 Zulip | 1 Zulip Server | 2026-06-17 | N/A | 7.5 HIGH |
| Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. | |||||
| CVE-2024-36611 | 2026-06-17 | N/A | 7.5 HIGH | ||
| In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report. | |||||
| CVE-2024-36604 | 1 Tenda | 2 O3, O3 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges. | |||||
| CVE-2024-36600 | 1 Gnu | 1 Libcdio | 2026-06-17 | N/A | 8.4 HIGH |
| Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file. | |||||
| CVE-2024-36599 | 1 Aegon | 1 Life Insurance Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php. | |||||
| CVE-2024-36598 | 2026-06-17 | N/A | 8.1 HIGH | ||
| An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file. | |||||
