Total
401054 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-60917 | 1 Craws | 1 Openatlas | 2026-06-17 | N/A | 4.6 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color parameter. | |||||
| CVE-2025-60916 | 1 Craws | 1 Openatlas | 2026-06-17 | N/A | 5.4 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter. | |||||
| CVE-2025-60915 | 1 Craws | 1 Openatlas | 2026-06-17 | N/A | 8.1 HIGH |
| An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request. | |||||
| CVE-2025-60914 | 1 Craws | 1 Openatlas | 2026-06-17 | N/A | 4.6 MEDIUM |
| Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint. | |||||
| CVE-2025-60912 | 1 Phpipam | 1 Phpipam | 2026-06-17 | N/A | 3.3 LOW |
| phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session. | |||||
| CVE-2025-60892 | 2026-06-17 | N/A | 6.8 MEDIUM | ||
| An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device. | |||||
| CVE-2025-60880 | 1 Webkul | 1 Bagisto | 2026-06-17 | N/A | 8.3 HIGH |
| An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions. | |||||
| CVE-2025-60876 | 1 Busybox | 1 Busybox | 2026-06-17 | N/A | 6.5 MEDIUM |
| BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). | |||||
| CVE-2025-60869 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the browsers of remote visitors viewing the generated static site. | |||||
| CVE-2025-60868 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service. | |||||
| CVE-2025-60865 | 1 Avanquest | 1 Pc Helpsoft Driver Updater | 2026-06-17 | N/A | 7.8 HIGH |
| Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. | |||||
| CVE-2025-60859 | 1 Sir | 1 Gnuboard | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php. | |||||
| CVE-2025-60858 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing attackers to intercept or extract sensitive information. | |||||
| CVE-2025-60856 | 2026-06-17 | N/A | 6.8 MEDIUM | ||
| Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface and execute arbitrary commands with root privileges. NOTE: this is disputed by the Supplier because of "certain restrictions on users privately connecting serial port cables" and because "the root user has a password and it meets the requirements of password security complexity." | |||||
| CVE-2025-60855 | 2026-06-17 | N/A | 5.1 MEDIUM | ||
| Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification." | |||||
| CVE-2025-60854 | 1 Dlink | 2 R15, R15 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd. | |||||
| CVE-2025-60852 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize user-controlled input before including it in CSV exports. This issue could lead to code execution on the system where the exported CSV file is opened. | |||||
| CVE-2025-60834 | 1 Ghostxbh | 1 Uzy-ssm-mall | 2026-06-17 | N/A | 6.5 MEDIUM |
| A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input. | |||||
| CVE-2025-60833 | 1 Ghostxbh | 1 Uzy-ssm-mall | 2026-06-17 | N/A | 6.5 MEDIUM |
| An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data. | |||||
| CVE-2025-60830 | 1 Redragon-erp | 1 Redragon-erp | 2026-06-17 | N/A | 6.5 MEDIUM |
| redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key. | |||||
