Vulnerabilities (CVE)

Filtered by CWE-94
Total 7144 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2087 1 Starsea99 1 Starsea-mall 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/goods/update. The manipulation of the argument goodsName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2086 1 Starsea99 1 Starsea-mall 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown code of the file /admin/indexConfigs/update. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2085 1 Starsea99 1 Starsea-mall 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of the file /admin/carousels/save. The manipulation of the argument redirectUrl leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2084 1 Phpgurukul 1 Human Metapneumovirus 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /search-report.php of the component Search Report Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2061 1 Fabian 1 Online Ticket Reservation System 2026-06-17 5.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /passenger.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2049 1 Code-projects 1 Blood Bank System 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file AB+.php. The manipulation of the argument Bloodname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2047 1 Phpgurukul 1 Art Gallery Management System 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-29902 2026-06-17 N/A 10.0 CRITICAL
Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.
CVE-2025-29807 1 Microsoft 1 Dataverse 2026-06-17 N/A 8.7 HIGH
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
CVE-2025-29806 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 6.5 MEDIUM
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2025-29662 1 Landchat 1 Landchat 2026-06-17 N/A 9.8 CRITICAL
A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.
CVE-2025-29661 1 Litepublisher 1 Litepubl Cms 2026-06-17 N/A 7.2 HIGH
Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
CVE-2025-29631 2026-06-17 N/A 9.8 CRITICAL
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit.
CVE-2025-29629 2026-06-17 N/A 9.1 CRITICAL
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
CVE-2025-29401 1 Emlog 1 Emlog 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-29306 1 Foxcms 1 Foxcms 2026-06-17 N/A 9.8 CRITICAL
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
CVE-2025-29281 1 Perfree 1 Perfreeblog 2026-06-17 N/A 8.8 HIGH
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.
CVE-2025-29064 1 Totolink 2 X18, X18 Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.
CVE-2025-29058 1 Qimou Cms Project 1 Qimou Cms 2026-06-17 N/A 9.8 CRITICAL
An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.
CVE-2025-29039 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 7.2 HIGH
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8