Vulnerabilities (CVE)

Total 401256 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-63593 1 Getgrav 1 Grav 2026-06-17 N/A 6.1 MEDIUM
Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-63589 1 Cmsimple-xh 1 Cmsimple Xh 2026-06-17 N/A 7.1 HIGH
A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the URL path is reflected into multiple HTML elements, allowing execution of arbitrary JavaScript in victims' browsers visiting a crafted URL.
CVE-2025-63588 1 Cmsimple-xh 1 Cmsimple Xh 2026-06-17 N/A 7.1 HIGH
An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.
CVE-2025-63585 1 Opensource-socialnetwork 1 Open Source Social Network 2026-06-17 N/A 6.5 MEDIUM
OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.
CVE-2025-63563 1 Summerpearlgroup 1 Vacation Rental Management Platform 2026-06-17 N/A 6.5 MEDIUM
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.
CVE-2025-63562 1 Summerpearlgroup 1 Vacation Rental Management Platform 2026-06-17 N/A 6.3 MEDIUM
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).
CVE-2025-63561 1 Summerpearlgroup 1 Vacation Rental Management Platform 2026-06-17 N/A 7.5 HIGH
Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s connection pool and worker capacity, preventing legitimate users and APIs from accessing the service.
CVE-2025-63551 1 Metinfo 1 Metinfo 2026-06-17 N/A 7.5 HIGH
A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces the server to initiate an HTTP request to an arbitrary internal or external network address. Successful exploitation could lead to internal network reconnaissance, port scanning, or the retrieval of sensitive information. The vulnerability may be present in the backend API called by or associated with the path `/admin/#/webset/?head_tab_active=0`, where user-provided XML data is processed.
CVE-2025-63548 2026-06-17 N/A 7.5 HIGH
An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean field.
CVE-2025-63547 2026-06-17 N/A 7.5 HIGH
An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted packet to the MTU length field
CVE-2025-63544 1 Nooncarlett 1 Techstore 2026-06-17 N/A 6.1 MEDIUM
TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.
CVE-2025-63543 1 Nooncarlett 1 Techstore 2026-06-17 N/A 6.1 MEDIUM
TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter.
CVE-2025-63535 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 9.6 CRITICAL
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.
CVE-2025-63534 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 8.5 HIGH
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg and error parameters, which are then executed in the victim's browser when the page is viewed.
CVE-2025-63533 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 8.5 HIGH
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and rprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the rname, remail, rpassword, rphone, rcity parameters, which are then executed in the victim's browser when the page is viewed.
CVE-2025-63532 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 9.6 CRITICAL
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.
CVE-2025-63531 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 10.0 CRITICAL
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass authentication and gain unauthorized access to the system.
CVE-2025-63529 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 6.1 MEDIUM
A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.
CVE-2025-63528 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 8.5 HIGH
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the error parameter, which is then executed in the victim's browser when the page is viewed.
CVE-2025-63527 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 8.5 HIGH
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the hname, hemail, hpassword, hphone, hcity parameters, which are then executed in the victim's browser when the page is viewed.