Vulnerabilities (CVE)

Total 401037 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-60318 1 Mayurik 1 Pet Grooming Management Software 2026-06-17 N/A 6.1 MEDIUM
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.
CVE-2025-60316 1 Mayurik 1 Pet Grooming Management Software 2026-06-17 N/A 9.4 CRITICAL
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.
CVE-2025-60314 1 Configuroweb 1 Simple Web Inventory System 2026-06-17 N/A 5.4 MEDIUM
Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript.
CVE-2025-60313 1 Rems 1 Link Status Checker 2026-06-17 N/A 6.1 MEDIUM
Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker to execute arbitrary code.
CVE-2025-60312 1 Rems 1 Markdown To Html Converter 2026-06-17 N/A 6.1 MEDIUM
Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Convert to HTML" button.
CVE-2025-60311 1 Projectworlds 1 Gym Management System 2026-06-17 N/A 8.8 HIGH
ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page
CVE-2025-60299 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 5.4 MEDIUM
Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.
CVE-2025-60298 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 5.4 MEDIUM
Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
CVE-2025-60291 2026-06-17 N/A 9.1 CRITICAL
An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations.
CVE-2025-60280 1 Hockeycomputindo 1 Bang Resto 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly in the browser. When exploited, an attacker can steal session cookies, redirect users to malicious sites, perform actions on behalf of the user, or deface the website. This can lead to user data compromise, loss of user trust, and a broader attack surface for more advanced exploitation techniques.
CVE-2025-60279 2026-06-17 N/A 9.6 CRITICAL
A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests to internal services via the API. An attacker can leverage this to enumerate open ports based on response discrepancies and interact with internal services.
CVE-2025-60269 1 Huayi-tec 1 Jeewms 2026-06-17 N/A 9.4 CRITICAL
JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.
CVE-2025-60268 1 Huayi-tec 1 Jeewms 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
CVE-2025-60267 1 Bestfeng 1 Xckk 2026-06-17 N/A 6.5 MEDIUM
In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered, resulting in a SQL injection vulnerability.
CVE-2025-60266 1 Bestfeng 1 Xckk 2026-06-17 N/A 6.5 MEDIUM
In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filtered, resulting in a SQL injection vulnerability.
CVE-2025-60265 1 Bestfeng 1 Xckk 2026-06-17 N/A 6.5 MEDIUM
In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtered, resulting in a SQL injection vulnerability.
CVE-2025-60262 1 H3c 4 Magic Ba1500l, Magic Ba1500l Firmware, Mc102-g and 1 more 2026-06-17 N/A 9.8 CRITICAL
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.
CVE-2025-60251 2026-06-17 N/A 5.0 MEDIUM
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
CVE-2025-60250 2026-06-17 N/A 4.7 MEDIUM
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.
CVE-2025-60248 2026-06-17 N/A 7.5 HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 3.1.3.