Total
401257 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-63690 | 1 Pig4cloud | 1 Pig | 2026-06-17 | N/A | 9.1 CRITICAL |
| In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is possible to execute any Java class with a parameterless constructor and its methods with parameter type String through reflection. At this time, the eval method in Tomcat's built-in class jakarta.el.ELProcessor can be used to execute commands, leading to a remote code execution vulnerability. | |||||
| CVE-2025-63689 | 1 Ycf1998 | 1 Money-pos | 2026-06-17 | N/A | 10.0 CRITICAL |
| Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter | |||||
| CVE-2025-63687 | 1 Rymcu | 1 Forest | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts. | |||||
| CVE-2025-63686 | 1 Guominjim | 1 Personmanage | 2026-06-17 | N/A | 6.5 MEDIUM |
| There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in the PersonManage system. | |||||
| CVE-2025-63685 | 1 Quark | 1 Quark Cloud Drive | 2026-06-17 | N/A | 9.8 CRITICAL |
| Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program. | |||||
| CVE-2025-63681 | 1 Openwebui | 1 Open Webui | 2026-06-17 | N/A | 4.3 MEDIUM |
| open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks. | |||||
| CVE-2025-63680 | 1 Nero | 1 Backitup | 2026-06-17 | N/A | 8.6 HIGH |
| Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback extension resolution, leads to arbitrary code execution when a user clicks a crafted entry. By creating a trailing-dot folder and placing a same-basename script, Nero BackItUp renders the file as a folder icon and then invokes ShellExecuteW, which executes the script via PATHEXT fallback (.COM/.EXE/.BAT/.CMD). The issue affects recent Nero BackItUp product lines (2019-2025 and earlier) and has been acknowledged by the vendor. | |||||
| CVE-2025-63679 | 1 Free5gc | 1 Free5gc | 2026-06-17 | N/A | 7.5 HIGH |
| free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes. | |||||
| CVE-2025-63678 | 1 Cmsmadesimple | 1 File Manager | 2026-06-17 | N/A | 7.2 HIGH |
| An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file. | |||||
| CVE-2025-63675 | 1 Netinvent | 1 Cryptidy | 2026-06-17 | N/A | 6.9 MEDIUM |
| cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py. | |||||
| CVE-2025-63667 | 3 Asecam, Keview, Simicam | 6 Ip Camera, Ip Camera Firmware, Ip Camera and 3 more | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication. | |||||
| CVE-2025-63666 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources. | |||||
| CVE-2025-63665 | 1 Gtedge | 1 Gt Edge Ai | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window. | |||||
| CVE-2025-63664 | 1 Gtedge | 1 Gt Edge Ai | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents. | |||||
| CVE-2025-63663 | 1 Gtedge | 1 Gt Edge Ai | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files. | |||||
| CVE-2025-63662 | 1 Gtedge | 1 Gt Edge Ai | 2026-06-17 | N/A | 7.5 HIGH |
| Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive information. | |||||
| CVE-2025-63658 | 1 Monkey-project | 1 Monkey | 2026-06-17 | N/A | 7.5 HIGH |
| A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |||||
| CVE-2025-63657 | 1 Monkey-project | 1 Monkey | 2026-06-17 | N/A | 7.5 HIGH |
| An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |||||
| CVE-2025-63656 | 1 Monkey-project | 1 Monkey | 2026-06-17 | N/A | 7.5 HIGH |
| An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |||||
| CVE-2025-63655 | 1 Monkey-project | 1 Monkey | 2026-06-17 | N/A | 7.5 HIGH |
| A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |||||
