Total
398446 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-25209 | 1 Rems | 1 Barangay Population Monitoring System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php. | |||||
| CVE-2024-25208 | 1 Barangay Management System Project | 1 Barangay Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter. | |||||
| CVE-2024-25207 | 1 Barangay Management System Project | 1 Barangay Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Contact Number parameter. | |||||
| CVE-2024-25202 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar. | |||||
| CVE-2024-25201 | 1 Espruino | 1 Espruino | 2026-06-17 | N/A | 7.5 HIGH |
| Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c. | |||||
| CVE-2024-25200 | 1 Espruino | 1 Espruino | 2026-06-17 | N/A | 7.5 HIGH |
| Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c. | |||||
| CVE-2024-25199 | 2 Opennav, Openrobotics | 2 Nav2, Robot Operating System | 2026-06-17 | N/A | 8.1 HIGH |
| Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. | |||||
| CVE-2024-25198 | 2 Opennav, Openrobotics | 2 Nav2, Robot Operating System | 2026-06-17 | N/A | 9.1 CRITICAL |
| Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. | |||||
| CVE-2024-25197 | 2 Opennav, Openrobotics | 2 Nav2, Robot Operating System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp. | |||||
| CVE-2024-25196 | 2 Opennav, Openrobotics | 2 Nav2, Robot Operating System | 2026-06-17 | N/A | 3.3 LOW |
| Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file. | |||||
| CVE-2024-25191 | 1 Zihanggao | 1 Php-jwt | 2026-06-17 | N/A | 9.8 CRITICAL |
| php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel. | |||||
| CVE-2024-25190 | 1 Glitchedpolygons | 1 L8w8jwt | 2026-06-17 | N/A | 9.8 CRITICAL |
| l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel. | |||||
| CVE-2024-25189 | 2 Debian, Libjwt | 2 Debian Linux, Libjwt | 2026-06-17 | N/A | 9.8 CRITICAL |
| libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel. | |||||
| CVE-2024-25187 | 1 Xiaocheng-keji | 1 71cms | 2026-06-17 | N/A | 8.6 HIGH |
| Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html. | |||||
| CVE-2024-25183 | 1 Vvveb | 1 Vvvebjs | 2026-06-17 | N/A | 7.5 HIGH |
| givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php. | |||||
| CVE-2024-25182 | 1 Vvveb | 1 Vvvebjs | 2026-06-17 | N/A | 9.8 CRITICAL |
| givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. | |||||
| CVE-2024-25181 | 1 Vvveb | 1 Vvvebjs | 2026-06-17 | N/A | 9.1 CRITICAL |
| A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file. | |||||
| CVE-2024-25180 | 1 Pdfmake Project | 1 Pdfmake | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers. | |||||
| CVE-2024-25178 | 1 Luajit | 1 Luajit | 2026-06-17 | N/A | 9.1 CRITICAL |
| LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c. | |||||
| CVE-2024-25177 | 1 Luajit | 1 Luajit | 2026-06-17 | N/A | 7.5 HIGH |
| LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS). | |||||
