Total
401057 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-61181 | 1 Daicuo | 1 Daicuo | 2026-06-17 | N/A | 6.5 MEDIUM |
| daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature. | |||||
| CVE-2025-61166 | 1 Ascertia | 1 Signinghub | 2026-06-17 | N/A | 6.1 MEDIUM |
| An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL. | |||||
| CVE-2025-61161 | 2026-06-17 | N/A | 8.4 HIGH | ||
| DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot. | |||||
| CVE-2025-61156 | 2026-06-17 | N/A | 7.8 HIGH | ||
| Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL. | |||||
| CVE-2025-61155 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests. These requests are executed in kernel-mode context without proper authentication or access validation, allowing the attacker to terminate arbitrary processes, including critical system and security services, without requiring administrative privileges. | |||||
| CVE-2025-61154 | 1 Gnu | 1 Libredwg | 2026-06-17 | N/A | 6.5 MEDIUM |
| Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c. | |||||
| CVE-2025-61152 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthorized access in applications that rely on python-jose for token validation. This issue is exploitable unless developers explicitly reject 'alg=none' tokens, which is not enforced by the library. NOTE: all parties agree that the issue is not relevant because it only occurs in a "verify_signature": False situation. | |||||
| CVE-2025-61148 | 1 Edupluscampus | 1 Edupluscampus | 2026-06-17 | N/A | 6.5 MEDIUM |
| An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint. | |||||
| CVE-2025-61147 | 1 Struktur | 1 Libde265 | 2026-06-17 | N/A | 6.2 MEDIUM |
| strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). | |||||
| CVE-2025-61146 | 1 Saitoha | 1 Libsixel | 2026-06-17 | N/A | 4.0 MEDIUM |
| saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c. | |||||
| CVE-2025-61145 | 1 Libtiff | 1 Libtiff | 2026-06-17 | N/A | 5.0 MEDIUM |
| libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c. | |||||
| CVE-2025-61144 | 1 Libtiff | 1 Libtiff | 2026-06-17 | N/A | 7.3 HIGH |
| libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function. | |||||
| CVE-2025-61143 | 1 Libtiff | 1 Libtiff | 2026-06-17 | N/A | 5.5 MEDIUM |
| libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c. | |||||
| CVE-2025-61141 | 2026-06-17 | N/A | 7.5 HIGH | ||
| sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variable and config file path to sh -c without sanitization, allowing attackers to execute arbitrary commands. | |||||
| CVE-2025-61138 | 1 Qlik | 1 Qlik Sense | 2026-06-17 | N/A | 7.5 HIGH |
| Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory. | |||||
| CVE-2025-61136 | 2026-06-17 | N/A | 7.1 HIGH | ||
| A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME. | |||||
| CVE-2025-61132 | 2026-06-17 | N/A | 7.1 HIGH | ||
| A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links without a fixed SERVER_NAME. | |||||
| CVE-2025-61128 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other wavlink models allows attackers to execute arbitrary code via crafted referrer value POST to login.cgi. | |||||
| CVE-2025-61121 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handling of cloud service credentials may allow attackers to obtain them and carry out unauthorized actions, such as sensitive information disclosure and abuse of cloud resources. Successful exploitation could result in privacy breaches and misuse of the platform infrastructure. | |||||
| CVE-2025-61120 | 2026-06-17 | N/A | 7.5 HIGH | ||
| AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes make brute-force account logins feasible. Successful exploitation could result in account compromise, privacy breaches, and abuse of cloud resources. | |||||
