Vulnerabilities (CVE)

Total 396425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36597 1 Projectworlds 1 Life Insurance Management System 2026-06-17 N/A 8.8 HIGH
Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
CVE-2024-36589 2026-06-17 N/A 4.3 MEDIUM
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.
CVE-2024-36588 2026-06-17 N/A 6.5 MEDIUM
An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.
CVE-2024-36587 2026-06-17 N/A 7.8 HIGH
Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.
CVE-2024-36586 2026-06-17 N/A 8.8 HIGH
An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.
CVE-2024-36583 2026-06-17 N/A 8.1 HIGH
A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.
CVE-2024-36582 2026-06-17 N/A 9.8 CRITICAL
alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)
CVE-2024-36581 2026-06-17 N/A 7.6 HIGH
A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.
CVE-2024-36580 2026-06-17 N/A 9.8 CRITICAL
A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
CVE-2024-36578 2026-06-17 N/A 5.9 MEDIUM
akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.
CVE-2024-36577 2026-06-17 N/A 8.3 HIGH
apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
CVE-2024-36575 2026-06-17 N/A 9.8 CRITICAL
A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.
CVE-2024-36574 2026-06-17 N/A 6.3 MEDIUM
A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)
CVE-2024-36573 2026-06-17 N/A 9.8 CRITICAL
almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.
CVE-2024-36572 1 Allpro 1 Formmanager Data Handler 2026-06-17 N/A 9.8 CRITICAL
Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.
CVE-2024-36569 1 Mayurik 1 Gas Agency Management System 2026-06-17 N/A 8.1 HIGH
Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.
CVE-2024-36568 1 Mayurik 1 Gas Agency Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
CVE-2024-36558 2026-06-17 N/A 7.5 HIGH
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.
CVE-2024-36557 2026-06-17 N/A 6.6 MEDIUM
The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.
CVE-2024-36556 2026-06-17 N/A 9.1 CRITICAL
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.