Total
401169 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-62787 | 1 Wazuh | 1 Wazuh | 2026-06-17 | N/A | 7.5 HIGH |
| Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect. A compromised agent can cause a READ operation beyond the end of the allocated buffer (which may contain sensitive information) by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can cause a buffer over-read and potentially access sensitive data. While the buffer over-read is always triggered while resolving the arguments of mdebug2, specific configuration options (analysisd.debug=2) need to be in place for the respective data to be leaked. This vulnerability is fixed in 4.10.2. | |||||
| CVE-2025-62786 | 1 Wazuh | 1 Wazuh | 2026-06-17 | N/A | 8.1 HIGH |
| Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writing a NULL byte 2 bytes before the start of the buffer allocated to decoded_it. A compromised agent can potentially leverage this issue to perform remote code execution, by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can leverage this issue to potentially achieve remote code execution on the wazuh manager (the exploitability of this vulnerability depends on the specifics of the respective heap allocator). This vulnerability is fixed in 4.10.2. | |||||
| CVE-2025-62785 | 1 Wazuh | 1 Wazuh | 2026-06-17 | N/A | 7.5 HIGH |
| Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation does not check whether value is NULL or not before calling os_strdup() on it. A compromised agent can cause a crash of analysisd by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can cause analysisd to crash and make it unavailable. This vulnerability is fixed in 4.10.2. | |||||
| CVE-2025-62784 | 1 Phoenix616 | 1 Inventorygui | 2026-06-17 | N/A | 5.3 MEDIUM |
| InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5. | |||||
| CVE-2025-62783 | 1 Phoenix616 | 1 Inventorygui | 2026-06-17 | N/A | 5.0 MEDIUM |
| InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.1-SNAPSHOT and earlier contain a vulnerability where any plugin using the `GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.2-SNAPSHOT. | |||||
| CVE-2025-62782 | 1 Phoenix616 | 1 Inventorygui | 2026-06-17 | N/A | 5.3 MEDIUM |
| InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.4-SNAPSHOT. | |||||
| CVE-2025-62781 | 1 Thm | 1 Pilos | 2026-06-17 | N/A | 5.0 MEDIUM |
| PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except for the currently active one. However, the current session’s token remains valid and is not refreshed. If an attacker has previously obtained this session token through another vulnerability, changing the password will not invalidate their access. As a result, the attacker can continue to act as the user even after the password has been changed. This vulnerability is fixed in 4.8.0. | |||||
| CVE-2025-62780 | 1 Changedetection | 1 Changedetection | 2026-06-17 | N/A | 3.5 LOW |
| changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions prior to 0.50.34 due to insufficient security checks. Two scenarios are possible. In the first, an attacker can insert a new watch with an arbitrary URL which really points to a web page. Once the HTML content is retrieved, the attacker updates the URL with a JavaScript payload. In the second, an attacker substitutes the URL in an existing watch with a new URL that is in reality a JavaScript payload. When the user clicks on *Preview* and then on the malicious link, the JavaScript malicious code is executed. Version 0.50.34 fixes the issue. | |||||
| CVE-2025-62779 | 1 Frappe | 1 Learning | 2026-06-17 | N/A | 5.4 MEDIUM |
| Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through input fields in the Job Form. | |||||
| CVE-2025-62778 | 1 Frappe | 1 Learning | 2026-06-17 | N/A | 5.3 MEDIUM |
| Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL. | |||||
| CVE-2025-62777 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affected device via Telnet and execute arbitrary commands. | |||||
| CVE-2025-62776 | 2026-06-17 | N/A | 7.8 HIGH | ||
| The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application. | |||||
| CVE-2025-62775 | 2026-06-17 | N/A | 8.0 HIGH | ||
| Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password. | |||||
| CVE-2025-62774 | 2026-06-17 | N/A | 3.1 LOW | ||
| On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps. | |||||
| CVE-2025-62773 | 2026-06-17 | N/A | 2.4 LOW | ||
| Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator. | |||||
| CVE-2025-62772 | 2026-06-17 | N/A | 3.1 LOW | ||
| On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases. | |||||
| CVE-2025-62771 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks. | |||||
| CVE-2025-62765 | 2026-06-17 | N/A | 7.5 HIGH | ||
| General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials. | |||||
| CVE-2025-62763 | 2026-06-17 | N/A | 5.0 MEDIUM | ||
| Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy. | |||||
| CVE-2025-62762 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in photoboxone SMTP Mail smtp-mail allows Cross Site Request Forgery.This issue affects SMTP Mail: from n/a through <= 1.3.51. | |||||
