Vulnerabilities (CVE)

Total 398379 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28662 1 Piwigo 1 Piwigo 2026-06-17 N/A 5.4 MEDIUM
A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.
CVE-2024-28640 1 Totolink 4 A7000r, A7000r Firmware, X5000r and 1 more 2026-06-17 N/A 7.5 HIGH
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
CVE-2024-28639 1 Totolink 4 A7000r, A7000r Firmware, X5000r and 1 more 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.
CVE-2024-28635 1 Devsoftbaltic 1 Survey-creator 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.
CVE-2024-28627 2026-06-17 N/A 7.5 HIGH
An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.
CVE-2024-28623 1 Ritecms 1 Ritecms 2026-06-17 N/A 6.1 MEDIUM
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
CVE-2024-28613 1 Mayurik 1 Php Task Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.
CVE-2024-28607 2026-06-17 N/A 2.9 LOW
The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.
CVE-2024-28595 1 Walterjnr1 1 Employee Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.
CVE-2024-28593 1 Moodle 1 Moodle 2026-06-17 N/A 5.4 MEDIUM
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
CVE-2024-28589 2026-06-17 N/A 6.7 MEDIUM
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.
CVE-2024-28584 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 3.3 LOW
Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the J2KImageToFIBITMAP() function when reading images in J2K format.
CVE-2024-28583 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 7.8 HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in XPM format.
CVE-2024-28582 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 8.4 HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in HDR format.
CVE-2024-28581 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 8.4 HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in TARGA format.
CVE-2024-28580 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 8.4 HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in RAS format.
CVE-2024-28579 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 6.2 MEDIUM
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the FreeImage_Unload() function when reading images in HDR format.
CVE-2024-28578 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 8.4 HIGH
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.
CVE-2024-28577 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 5.5 MEDIUM
Null Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the jpeg_read_exif_profile_raw() function when reading images in JPEG format.
CVE-2024-28576 1 Freeimage Project 1 Freeimage 2026-06-17 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the opj_j2k_tcp_destroy() function when reading images in J2K format.