Total
401256 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-63526 | 1 Shridharshukl | 1 Blood Bank Management System | 2026-06-17 | N/A | 8.5 HIGH |
| A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg parameter, which is then executed in the victim's browser when the page is viewed. | |||||
| CVE-2025-63525 | 1 Shridharshukl | 1 Blood Bank Management System | 2026-06-17 | N/A | 9.6 CRITICAL |
| An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php. | |||||
| CVE-2025-63523 | 1 Feehi | 1 Feehicms | 2026-06-17 | N/A | 6.5 MEDIUM |
| FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes. | |||||
| CVE-2025-63522 | 1 Feehi | 1 Feehicms | 2026-06-17 | N/A | 4.6 MEDIUM |
| Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function | |||||
| CVE-2025-63520 | 1 Feehi | 1 Feehicms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate). | |||||
| CVE-2025-63514 | 1 Kishan0725 | 1 Hospital Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter. | |||||
| CVE-2025-63513 | 1 Kishan0725 | 1 Hospital Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. | |||||
| CVE-2025-63512 | 1 Kishan0725 | 1 Hospital Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into a dynamic SQL query. | |||||
| CVE-2025-63499 | 1 Alinto | 1 Sogo | 2026-06-17 | N/A | 6.1 MEDIUM |
| Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. | |||||
| CVE-2025-63498 | 2 Alinto, Debian | 2 Sogo, Debian Linux | 2026-06-17 | N/A | 6.1 MEDIUM |
| alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. | |||||
| CVE-2025-63497 | 1 Rickxy | 1 Hospital Management System | 2026-06-17 | N/A | 7.1 HIGH |
| The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries. | |||||
| CVE-2025-63469 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63468 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63467 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63466 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63465 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63464 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63463 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63462 | 1 Totolink | 2 A7000r, A7000r Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
| CVE-2025-63461 | 1 Totolink | 2 A7000r, A7000r Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |||||
