Total
398385 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-28323 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks. | |||||
| CVE-2024-28322 | 1 Puneethreddyhc | 1 Event Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request. | |||||
| CVE-2024-28320 | 1 Mayurik | 1 Hospital Management System | 2026-06-17 | N/A | 7.6 HIGH |
| Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php. | |||||
| CVE-2024-28319 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 6.2 MEDIUM |
| gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374 | |||||
| CVE-2024-28318 | 1 Gpac | 1 Gpac | 2026-06-17 | N/A | 7.1 HIGH |
| gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swf_parse.c:325 | |||||
| CVE-2024-28303 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php. | |||||
| CVE-2024-28298 | 1 E-bmsoft | 1 Bmplanning | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest. | |||||
| CVE-2024-28297 | 2026-06-17 | N/A | 7.5 HIGH | ||
| SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
| CVE-2024-28294 | 1 Limbas | 1 Limbas | 2026-06-17 | N/A | 6.5 MEDIUM |
| Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter. | |||||
| CVE-2024-28288 | 1 Ruijie | 2 Rg-nbr700gw, Rg-nbr700gw Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise. | |||||
| CVE-2024-28287 | 2026-06-17 | N/A | 7.3 HIGH | ||
| A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL. | |||||
| CVE-2024-28286 | 1 Mz-automation | 1 Libiec61850 | 2026-06-17 | N/A | 7.5 HIGH |
| In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash | |||||
| CVE-2024-28285 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges. | |||||
| CVE-2024-28283 | 1 Linksys | 2 E1000, E1000 Firmware | 2026-06-17 | N/A | 6.7 MEDIUM |
| There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution. | |||||
| CVE-2024-28279 | 1 Carmelo | 1 Computer Book Store | 2026-06-17 | N/A | 7.3 HIGH |
| Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=. | |||||
| CVE-2024-28277 | 1 Remyandrade | 1 School Task Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads. | |||||
| CVE-2024-28276 | 1 Rems | 1 School Task Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=. | |||||
| CVE-2024-28275 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests. | |||||
| CVE-2024-28270 | 2026-06-17 | N/A | 8.1 HIGH | ||
| An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword. | |||||
| CVE-2024-28269 | 2026-06-17 | N/A | 7.2 HIGH | ||
| ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to upload of malicious files. This could result in a Remote Code Execution. | |||||
