Total
401037 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-60318 | 1 Mayurik | 1 Pet Grooming Management Software | 2026-06-17 | N/A | 6.1 MEDIUM |
| SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields. | |||||
| CVE-2025-60316 | 1 Mayurik | 1 Pet Grooming Management Software | 2026-06-17 | N/A | 9.4 CRITICAL |
| SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter. | |||||
| CVE-2025-60314 | 1 Configuroweb | 1 Simple Web Inventory System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript. | |||||
| CVE-2025-60313 | 1 Rems | 1 Link Status Checker | 2026-06-17 | N/A | 6.1 MEDIUM |
| Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker to execute arbitrary code. | |||||
| CVE-2025-60312 | 1 Rems | 1 Markdown To Html Converter | 2026-06-17 | N/A | 6.1 MEDIUM |
| Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Convert to HTML" button. | |||||
| CVE-2025-60311 | 1 Projectworlds | 1 Gym Management System | 2026-06-17 | N/A | 8.8 HIGH |
| ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page | |||||
| CVE-2025-60299 | 1 Xxyopen | 1 Novel-plus | 2026-06-17 | N/A | 5.4 MEDIUM |
| Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread. | |||||
| CVE-2025-60298 | 1 Xxyopen | 1 Novel-plus | 2026-06-17 | N/A | 5.4 MEDIUM |
| Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter. | |||||
| CVE-2025-60291 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations. | |||||
| CVE-2025-60280 | 1 Hockeycomputindo | 1 Bang Resto | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists due to insufficient input sanitization or output encoding, allowing attacker-controlled input to be rendered directly in the browser. When exploited, an attacker can steal session cookies, redirect users to malicious sites, perform actions on behalf of the user, or deface the website. This can lead to user data compromise, loss of user trust, and a broader attack surface for more advanced exploitation techniques. | |||||
| CVE-2025-60279 | 2026-06-17 | N/A | 9.6 CRITICAL | ||
| A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests to internal services via the API. An attacker can leverage this to enumerate open ports based on response discrepancies and interact with internal services. | |||||
| CVE-2025-60269 | 1 Huayi-tec | 1 Jeewms | 2026-06-17 | N/A | 9.4 CRITICAL |
| JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file. | |||||
| CVE-2025-60268 | 1 Huayi-tec | 1 Jeewms | 2026-06-17 | N/A | 6.5 MEDIUM |
| An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution. | |||||
| CVE-2025-60267 | 1 Bestfeng | 1 Xckk | 2026-06-17 | N/A | 6.5 MEDIUM |
| In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered, resulting in a SQL injection vulnerability. | |||||
| CVE-2025-60266 | 1 Bestfeng | 1 Xckk | 2026-06-17 | N/A | 6.5 MEDIUM |
| In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filtered, resulting in a SQL injection vulnerability. | |||||
| CVE-2025-60265 | 1 Bestfeng | 1 Xckk | 2026-06-17 | N/A | 6.5 MEDIUM |
| In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtered, resulting in a SQL injection vulnerability. | |||||
| CVE-2025-60262 | 1 H3c | 4 Magic Ba1500l, Magic Ba1500l Firmware, Mc102-g and 1 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices. | |||||
| CVE-2025-60251 | 2026-06-17 | N/A | 5.0 MEDIUM | ||
| Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring. | |||||
| CVE-2025-60250 | 2026-06-17 | N/A | 4.7 MEDIUM | ||
| Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV. | |||||
| CVE-2025-60248 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 3.1.3. | |||||
