Vulnerabilities (CVE)

Total 401256 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-63526 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 8.5 HIGH
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg parameter, which is then executed in the victim's browser when the page is viewed.
CVE-2025-63525 1 Shridharshukl 1 Blood Bank Management System 2026-06-17 N/A 9.6 CRITICAL
An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.
CVE-2025-63523 1 Feehi 1 Feehicms 2026-06-17 N/A 6.5 MEDIUM
FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes.
CVE-2025-63522 1 Feehi 1 Feehicms 2026-06-17 N/A 4.6 MEDIUM
Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
CVE-2025-63520 1 Feehi 1 Feehicms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).
CVE-2025-63514 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 6.1 MEDIUM
kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.
CVE-2025-63513 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 6.5 MEDIUM
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.
CVE-2025-63512 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 6.5 MEDIUM
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into a dynamic SQL query.
CVE-2025-63499 1 Alinto 1 Sogo 2026-06-17 N/A 6.1 MEDIUM
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
CVE-2025-63498 2 Alinto, Debian 2 Sogo, Debian Linux 2026-06-17 N/A 6.1 MEDIUM
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
CVE-2025-63497 1 Rickxy 1 Hospital Management System 2026-06-17 N/A 7.1 HIGH
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.
CVE-2025-63469 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63468 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63467 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63466 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63465 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63464 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63463 1 Totolink 2 Lr350, Lr350 Firmware 2026-06-17 N/A 7.5 HIGH
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63462 1 Totolink 2 A7000r, A7000r Firmware 2026-06-17 N/A 7.5 HIGH
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63461 1 Totolink 2 A7000r, A7000r Firmware 2026-06-17 N/A 7.5 HIGH
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.