Vulnerabilities (CVE)

Total 400665 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-59728 2026-06-17 N/A N/A
When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. This will write two bytes into the buffer, starting at the last valid byte in the buffer, writing the NUL byte beyond the end of the allocated buffer. We recommend upgrading to version 8.0 or beyond.
CVE-2025-59719 1 Fortinet 1 Fortiweb 2026-06-17 N/A 9.8 CRITICAL
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
CVE-2025-59718 2 Fortinet, Siemens 5 Fortios, Fortiproxy, Fortiswitchmanager and 2 more 2026-06-17 N/A 9.8 CRITICAL
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
CVE-2025-59717 1 Digitalocean 1 Do-markdownit 2026-06-17 N/A 5.4 MEDIUM
In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).
CVE-2025-59716 1 Owncloud 1 Guests 2026-06-17 N/A 5.3 MEDIUM
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a non-existent user.
CVE-2025-59715 1 Smseagle 1 Smseagle 2026-06-17 N/A 4.8 MEDIUM
SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.
CVE-2025-59714 1 Internet2 1 Grouper 2026-06-17 N/A 6.5 MEDIUM
In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
CVE-2025-59713 1 Snipeitapp 1 Snipe-it 2026-06-17 N/A 6.8 MEDIUM
Snipe-IT before 8.1.18 allows unsafe deserialization.
CVE-2025-59712 1 Snipeitapp 1 Snipe-it 2026-06-17 N/A 6.4 MEDIUM
Snipe-IT before 8.1.18 allows XSS.
CVE-2025-59707 1 N2ws 1 N2w 2026-06-17 N/A 9.8 CRITICAL
In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.
CVE-2025-59706 1 N2ws 1 N2w 2026-06-17 N/A 9.8 CRITICAL
In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
CVE-2025-59692 2026-06-17 N/A 3.7 LOW
PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have been configured manually or by other software (e.g., UFW, container engines, or system security policies). Upon VPN disconnect, the original firewall state is not restored. As a result, the system may become unintentionally exposed to network traffic that was previously blocked. This affects CLI 2.0.1 and GUI 2.10.0.
CVE-2025-59691 2026-06-17 N/A 3.7 LOW
PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connected, but IPv6 traffic is no longer routed or blocked. In the GUI client, the IPv6 connection remains functional after disconnection until the user clicks Reconnect. In both cases, the real IPv6 address is exposed to external services, violating user privacy and defeating the advertised IPv6 leak protection. This affects CLI 2.0.1 and GUI 2.10.0.
CVE-2025-59689 1 Libraesva 1 Email Security Gateway 2026-06-17 N/A 6.1 MEDIUM
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
CVE-2025-59687 2026-06-17 N/A 4.3 MEDIUM
IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization.
CVE-2025-59686 2026-06-17 N/A 6.5 MEDIUM
Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.
CVE-2025-59685 2026-06-17 N/A 5.3 MEDIUM
Kazaar 1.25.12 allows a JWT with none in the alg field.
CVE-2025-59684 1 Digisign 1 Digisigner One 2026-06-17 N/A 8.8 HIGH
DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
CVE-2025-59682 1 Djangoproject 1 Django 2026-06-17 N/A 3.1 LOW
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.
CVE-2025-59681 1 Djangoproject 1 Django 2026-06-17 N/A 7.1 HIGH
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to these methods (on MySQL and MariaDB).