Vulnerabilities (CVE)

Total 401251 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-63454 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-63453 1 Car-booking-system-php Project 1 Car-booking-system-php 2026-06-17 N/A 9.8 CRITICAL
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.
CVE-2025-63452 1 Car-booking-system-php Project 1 Car-booking-system-php 2026-06-17 N/A 9.4 CRITICAL
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.
CVE-2025-63451 1 Car-booking-system-php Project 1 Car-booking-system-php 2026-06-17 N/A 9.8 CRITICAL
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.
CVE-2025-63450 1 Car-booking-system-php Project 1 Car-booking-system-php 2026-06-17 N/A 5.4 MEDIUM
Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
CVE-2025-63449 1 Water Management System Project 1 Water Management System 2026-06-17 N/A 5.4 MEDIUM
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
CVE-2025-63448 1 Water Management System Project 1 Water Management System 2026-06-17 N/A 6.1 MEDIUM
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
CVE-2025-63447 1 Water Management System Project 1 Water Management System 2026-06-17 N/A 6.1 MEDIUM
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
CVE-2025-63446 1 Water Management System Project 1 Water Management System 2026-06-17 N/A 6.1 MEDIUM
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.
CVE-2025-63443 1 School Management System Php Project 1 School Management System Php 2026-06-17 N/A 5.4 MEDIUM
School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.
CVE-2025-63442 1 Nababur 1 Simple-user-management-system 2026-06-17 N/A 4.6 MEDIUM
Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser
CVE-2025-63441 1 Opensource-socialnetwork 1 Open Source Social Network 2026-06-17 N/A 7.3 HIGH
Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.
CVE-2025-63435 1 Xtooltech 1 Xtool Anyscan 2026-06-17 N/A 4.3 MEDIUM
Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..
CVE-2025-63434 1 Xtooltech 1 Xtool Anyscan 2026-06-17 N/A 8.8 HIGH
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.
CVE-2025-63433 1 Xtooltech 1 Xtool Anyscan 2026-06-17 N/A 4.6 MEDIUM
Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.
CVE-2025-63432 1 Xtooltech 1 Xtool Anyscan 2026-06-17 N/A 4.6 MEDIUM
Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.
CVE-2025-63423 2026-06-17 N/A 7.5 HIGH
Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.
CVE-2025-63422 2026-06-17 N/A 7.5 HIGH
Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.
CVE-2025-63421 2026-06-17 N/A 7.8 HIGH
An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file
CVE-2025-63420 1 Crushftp 1 Crushftp 2026-06-17 N/A 4.1 MEDIUM
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.