Vulnerabilities (CVE)

Total 398446 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25209 1 Rems 1 Barangay Population Monitoring System 2026-06-17 N/A 9.8 CRITICAL
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.
CVE-2024-25208 1 Barangay Management System Project 1 Barangay Management System 2026-06-17 N/A 5.4 MEDIUM
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter.
CVE-2024-25207 1 Barangay Management System Project 1 Barangay Management System 2026-06-17 N/A 5.4 MEDIUM
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Contact Number parameter.
CVE-2024-25202 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.
CVE-2024-25201 1 Espruino 1 Espruino 2026-06-17 N/A 7.5 HIGH
Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.
CVE-2024-25200 1 Espruino 1 Espruino 2026-06-17 N/A 7.5 HIGH
Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.
CVE-2024-25199 2 Opennav, Openrobotics 2 Nav2, Robot Operating System 2026-06-17 N/A 8.1 HIGH
Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.
CVE-2024-25198 2 Opennav, Openrobotics 2 Nav2, Robot Operating System 2026-06-17 N/A 9.1 CRITICAL
Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.
CVE-2024-25197 2 Opennav, Openrobotics 2 Nav2, Robot Operating System 2026-06-17 N/A 6.5 MEDIUM
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.
CVE-2024-25196 2 Opennav, Openrobotics 2 Nav2, Robot Operating System 2026-06-17 N/A 3.3 LOW
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.
CVE-2024-25191 1 Zihanggao 1 Php-jwt 2026-06-17 N/A 9.8 CRITICAL
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
CVE-2024-25190 1 Glitchedpolygons 1 L8w8jwt 2026-06-17 N/A 9.8 CRITICAL
l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
CVE-2024-25189 2 Debian, Libjwt 2 Debian Linux, Libjwt 2026-06-17 N/A 9.8 CRITICAL
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
CVE-2024-25187 1 Xiaocheng-keji 1 71cms 2026-06-17 N/A 8.6 HIGH
Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html.
CVE-2024-25183 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 7.5 HIGH
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
CVE-2024-25182 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 9.8 CRITICAL
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
CVE-2024-25181 1 Vvveb 1 Vvvebjs 2026-06-17 N/A 9.1 CRITICAL
A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.
CVE-2024-25180 1 Pdfmake Project 1 Pdfmake 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.
CVE-2024-25178 1 Luajit 1 Luajit 2026-06-17 N/A 9.1 CRITICAL
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
CVE-2024-25177 1 Luajit 1 Luajit 2026-06-17 N/A 7.5 HIGH
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).