Total
401054 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-61044 | 1 Totolink | 2 X18, X18 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function. | |||||
| CVE-2025-61043 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper::GetUTF16FromUTF8 function. The issue arises from improper handling of the length of the input UTF-8 string, causing the function to read past the memory boundary. This vulnerability may result in a crash or expose sensitive data. | |||||
| CVE-2025-61037 | 1 Sevencs | 2 Ec2007 Kernel, Orca G2 | 2026-06-17 | N/A | 7.0 HIGH |
| A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license management logic. The regService process, which runs with SYSTEM privileges, creates a fixed directory and writes files without verifying whether the path is an NTFS reparse point. By exploiting this race condition, an attacker can replace the target directory with a junction pointing to a user-controlled path. This causes the SYSTEM-level process to drop binaries in a location fully controlled by the attacker, allowing arbitrary code execution with SYSTEM privileges. The vulnerability can be exploited by any standard user with only a single UAC confirmation, making it highly practical and dangerous in real-world environments. | |||||
| CVE-2025-61035 | 2026-06-17 | N/A | 7.7 HIGH | ||
| The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik file, which is created with mode 0777 and 0775 respectively, exposing secrets to other local users. Additionally, the .kimlik file is written without symlink checks, allowing local attackers to overwrite arbitrary files. This can result in information disclosure and denial of service. | |||||
| CVE-2025-60991 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter. | |||||
| CVE-2025-60983 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information" endpoints. | |||||
| CVE-2025-60982 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object references. Affected endpoints do not enforce proper authorization checks, allowing authenticated users to access or modify data belonging to other users by changing object identifiers in API requests. Attackers can exploit this flaw to view or modify sensitive records without proper authorization. | |||||
| CVE-2025-60954 | 1 Microweber | 1 Microweber | 2026-06-17 | N/A | 8.3 HIGH |
| Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts. | |||||
| CVE-2025-60950 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to execute arbitrary code via a crafted SVG file. | |||||
| CVE-2025-60949 | 1 Csprousers | 1 Csweb | 2026-06-17 | N/A | 9.1 CRITICAL |
| Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha. | |||||
| CVE-2025-60948 | 1 Csprousers | 1 Csweb | 2026-06-17 | N/A | 4.6 MEDIUM |
| Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha. | |||||
| CVE-2025-60947 | 1 Csprousers | 1 Csweb | 2026-06-17 | N/A | 8.8 HIGH |
| Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha. | |||||
| CVE-2025-60946 | 1 Csprousers | 1 Csweb | 2026-06-17 | N/A | 8.8 HIGH |
| Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. | |||||
| CVE-2025-60938 | 1 Openenergymonitor | 1 Emoncms | 2026-06-17 | N/A | 7.5 HIGH |
| Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset within the /admin/upload-custom-firmware endpoint. | |||||
| CVE-2025-60936 | 1 Openenergymonitor | 1 Emoncms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs. | |||||
| CVE-2025-60935 | 1 Returnfi | 1 Blitz | 2026-06-17 | N/A | 6.1 MEDIUM |
| An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication. | |||||
| CVE-2025-60934 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee Notes, title, or description parameters. The patched version is PP-Release-6.3.2.0. | |||||
| CVE-2025-60933 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and Goal Description parameters. The patched version is PP-Release-6.3.2.0. | |||||
| CVE-2025-60932 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and Goal Description parameters. The patched version is PP-Release-6.3.2.0. | |||||
| CVE-2025-60925 | 1 Codeshare | 1 Codeshare | 2026-06-17 | N/A | 5.3 MEDIUM |
| codeshare v1.0.0 was discovered to contain an information leakage vulnerability. | |||||
