Vulnerabilities (CVE)

Total 401257 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-63811 1 Dvsekhvalnov 1 Jose2go 2026-06-17 N/A 7.5 HIGH
An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.
CVE-2025-63807 1 2dogz 1 Blogin 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.
CVE-2025-63800 1 Opensourcepos 1 Open Source Point Of Sale 2026-06-17 N/A 7.5 HIGH
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.
CVE-2025-63785 1 Onlook 1 Onlook 2026-06-17 N/A 6.1 MEDIUM
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a text element. An attacker can exploit this to inject malicious HTML and script code, which is then executed within the context of the preview iframe, allowing for the execution of arbitrary scripts in the user's session.
CVE-2025-63784 1 Onlook 1 Onlook 2026-06-17 N/A 6.5 MEDIUM
An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation when constructing a redirect URL. A remote attacker can send a manipulated X-Forwarded-Host header to redirect an authenticated user to an arbitrary external website under their control, which can be exploited for phishing attacks.
CVE-2025-63783 1 Onlook 1 Onlook 2026-06-17 N/A 7.6 HIGH
A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently authenticated user for the requested project ID. An authenticated attacker can send a malicious request containing another user's project ID to unlawfully modify, delete, or manipulate tags on that project, which can severely compromise data integrity and availability.
CVE-2025-63757 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 7.5 HIGH
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
CVE-2025-63749 1 Pnetlab 1 Pnetlab 2026-06-17 N/A 6.5 MEDIUM
pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.
CVE-2025-63745 1 Radare 1 Radare2 2026-06-17 N/A 5.5 MEDIUM
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.
CVE-2025-63744 1 Radare 1 Radare2 2026-06-17 N/A 4.3 MEDIUM
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.
CVE-2025-63742 1 Rockoa 1 Rockoa 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.
CVE-2025-63740 1 Rockoa 1 Rockoa 2026-06-17 N/A 4.3 MEDIUM
SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the actstr parameter.
CVE-2025-63739 1 Rockoa 1 Rockoa 2026-06-17 N/A 4.3 MEDIUM
An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to authenticated users to modify PHP configuration files via the a parameter to the index.php endpoint.
CVE-2025-63738 1 Rockoa 1 Rockoa 2026-06-17 N/A 4.3 MEDIUM
An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive information via phpinfo via the a parameter to the index.php.
CVE-2025-63737 1 Rockoa 1 Rockoa 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 allows remote attackers to inject arbitrary web script or HTML via the m parameter to the task.php endpoint.
CVE-2025-63735 1 Ruckuswireless 1 Ruckus Unleashed 2026-06-17 N/A 6.1 MEDIUM
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.
CVE-2025-63729 1 Syrotech 2 Sy-gpon-1110-wdont, Sy-gpon-1110-wdont Firmware 2026-06-17 N/A 9.0 CRITICAL
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.
CVE-2025-63725 1 Radioinorr 1 Svx Portal 2026-06-17 N/A 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.
CVE-2025-63724 1 Radioinorr 1 Svx Portal 2026-06-17 N/A 6.0 MEDIUM
SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.
CVE-2025-63721 1 Hummerrisk 1 Hummerrisk 2026-06-17 N/A 8.8 HIGH
HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby achieve RCE and take over the server.