Vulnerabilities (CVE)

Total 398385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28323 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 6.5 MEDIUM
The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.
CVE-2024-28322 1 Puneethreddyhc 1 Event Management 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.
CVE-2024-28320 1 Mayurik 1 Hospital Management System 2026-06-17 N/A 7.6 HIGH
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.
CVE-2024-28319 1 Gpac 1 Gpac 2026-06-17 N/A 6.2 MEDIUM
gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374
CVE-2024-28318 1 Gpac 1 Gpac 2026-06-17 N/A 7.1 HIGH
gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swf_parse.c:325
CVE-2024-28303 2026-06-17 N/A 9.8 CRITICAL
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.
CVE-2024-28298 1 E-bmsoft 1 Bmplanning 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest.
CVE-2024-28297 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2024-28294 1 Limbas 1 Limbas 2026-06-17 N/A 6.5 MEDIUM
Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.
CVE-2024-28288 1 Ruijie 2 Rg-nbr700gw, Rg-nbr700gw Firmware 2026-06-17 N/A 9.8 CRITICAL
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise.
CVE-2024-28287 2026-06-17 N/A 7.3 HIGH
A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.
CVE-2024-28286 1 Mz-automation 1 Libiec61850 2026-06-17 N/A 7.5 HIGH
In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash
CVE-2024-28285 2026-06-17 N/A 9.8 CRITICAL
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.
CVE-2024-28283 1 Linksys 2 E1000, E1000 Firmware 2026-06-17 N/A 6.7 MEDIUM
There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.
CVE-2024-28279 1 Carmelo 1 Computer Book Store 2026-06-17 N/A 7.3 HIGH
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.
CVE-2024-28277 1 Remyandrade 1 School Task Manager 2026-06-17 N/A 6.1 MEDIUM
In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.
CVE-2024-28276 1 Rems 1 School Task Manager 2026-06-17 N/A 6.1 MEDIUM
Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.
CVE-2024-28275 2026-06-17 N/A 6.5 MEDIUM
Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.
CVE-2024-28270 2026-06-17 N/A 8.1 HIGH
An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.
CVE-2024-28269 2026-06-17 N/A 7.2 HIGH
ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to upload of malicious files. This could result in a Remote Code Execution.