Total
401535 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-63452 | 1 Car-booking-system-php Project | 1 Car-booking-system-php | 2026-06-17 | N/A | 9.4 CRITICAL |
| Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php. | |||||
| CVE-2025-63451 | 1 Car-booking-system-php Project | 1 Car-booking-system-php | 2026-06-17 | N/A | 9.8 CRITICAL |
| Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php. | |||||
| CVE-2025-63450 | 1 Car-booking-system-php Project | 1 Car-booking-system-php | 2026-06-17 | N/A | 5.4 MEDIUM |
| Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php. | |||||
| CVE-2025-63449 | 1 Water Management System Project | 1 Water Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php. | |||||
| CVE-2025-63448 | 1 Water Management System Project | 1 Water Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1. | |||||
| CVE-2025-63447 | 1 Water Management System Project | 1 Water Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php. | |||||
| CVE-2025-63446 | 1 Water Management System Project | 1 Water Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php. | |||||
| CVE-2025-63443 | 1 School Management System Php Project | 1 School Management System Php | 2026-06-17 | N/A | 5.4 MEDIUM |
| School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter. | |||||
| CVE-2025-63442 | 1 Nababur | 1 Simple-user-management-system | 2026-06-17 | N/A | 4.6 MEDIUM |
| Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser | |||||
| CVE-2025-63441 | 1 Opensource-socialnetwork | 1 Open Source Social Network | 2026-06-17 | N/A | 7.3 HIGH |
| Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends. | |||||
| CVE-2025-63435 | 1 Xtooltech | 1 Xtool Anyscan | 2026-06-17 | N/A | 4.3 MEDIUM |
| Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages.. | |||||
| CVE-2025-63434 | 1 Xtooltech | 1 Xtool Anyscan | 2026-06-17 | N/A | 8.8 HIGH |
| The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution. | |||||
| CVE-2025-63433 | 1 Xtooltech | 1 Xtool Anyscan | 2026-06-17 | N/A | 4.6 MEDIUM |
| Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package. | |||||
| CVE-2025-63432 | 1 Xtooltech | 1 Xtool Anyscan | 2026-06-17 | N/A | 4.6 MEDIUM |
| Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution. | |||||
| CVE-2025-63423 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password. | |||||
| CVE-2025-63422 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request. | |||||
| CVE-2025-63421 | 2026-06-17 | N/A | 7.8 HIGH | ||
| An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file | |||||
| CVE-2025-63420 | 1 Crushftp | 1 Crushftp | 2026-06-17 | N/A | 4.1 MEDIUM |
| CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions. | |||||
| CVE-2025-63419 | 1 Crushftp | 1 Crushftp | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection. | |||||
| CVE-2025-63418 | 1 Selfbest | 1 Selfbest | 2026-06-17 | N/A | 6.1 MEDIUM |
| A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitrary JavaScript in the context of a logged-in user's session by injecting payloads via the browser's developer console. The vulnerability arises from the application's client-side code being susceptible to direct DOM manipulation without adequate sanitization or a Content Security Policy (CSP), potentially leading to account takeover and data theft. | |||||
