Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25468 | 1 Totolink | 2 X5000r, X5000r Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component. | |||||
| CVE-2024-25466 | 1 React-native-documents | 1 Document Picker | 2026-06-17 | N/A | 7.8 HIGH |
| Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component. | |||||
| CVE-2024-25461 | 1 Creatio | 1 Crm Creatio | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component. | |||||
| CVE-2024-25458 | 2026-06-17 | N/A | 7.5 HIGH | ||
| An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0903 allows a remote attacker to obtain sensitive information via a crafted request to a UDP port. | |||||
| CVE-2024-25454 | 1 Axiosys | 1 Bento4 | 2026-06-17 | N/A | 5.5 MEDIUM |
| Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function. | |||||
| CVE-2024-25453 | 1 Axiosys | 1 Bento4 | 2026-06-17 | N/A | 5.5 MEDIUM |
| Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function. | |||||
| CVE-2024-25452 | 1 Axiosys | 1 Bento4 | 2026-06-17 | N/A | 5.5 MEDIUM |
| Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. | |||||
| CVE-2024-25451 | 1 Axiosys | 1 Bento4 | 2026-06-17 | N/A | 6.5 MEDIUM |
| Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function. | |||||
| CVE-2024-25450 | 1 Enlightenment | 1 Imlib2 | 2026-06-17 | N/A | 8.8 HIGH |
| imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts(). | |||||
| CVE-2024-25448 | 1 Enlightenment | 1 Imlib2 | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image. | |||||
| CVE-2024-25447 | 1 Enlightenment | 1 Imlib2 | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image. | |||||
| CVE-2024-25446 | 1 Hugin Project | 1 Hugin | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image. | |||||
| CVE-2024-25445 | 1 Hugin Project | 1 Hugin | 2026-06-17 | N/A | 7.8 HIGH |
| Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure. | |||||
| CVE-2024-25443 | 1 Hugin Project | 1 Hugin | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image. | |||||
| CVE-2024-25442 | 1 Hugin Project | 1 Hugin | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image. | |||||
| CVE-2024-25438 | 1 Public Knowledge Project | 1 Open Journal Systems | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |||||
| CVE-2024-25436 | 1 Sfu | 1 Open Journal Systems | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |||||
| CVE-2024-25435 | 1 Md1health | 1 Md1patient | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter. | |||||
| CVE-2024-25434 | 1 Pkp.sfu | 1 Open Journal Systems | 2026-06-17 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter. | |||||
| CVE-2024-25431 | 1 Bytecodealliance | 1 Webassembly Micro Runtime | 2026-06-17 | N/A | 7.8 HIGH |
| An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function. | |||||
