Total
400609 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-59307 | 2026-06-17 | N/A | 6.7 MEDIUM | ||
| RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |||||
| CVE-2025-59305 | 1 Langfuse | 1 Langfuse | 2026-06-17 | N/A | 7.6 HIGH |
| Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry. | |||||
| CVE-2025-59304 | 1 Swetrix | 1 Swetrix | 2026-06-17 | N/A | 9.8 CRITICAL |
| A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request. | |||||
| CVE-2025-59303 | 2026-06-17 | N/A | 6.4 MEDIUM | ||
| HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1. | |||||
| CVE-2025-59302 | 1 Apache | 1 Cloudstack | 2026-06-17 | N/A | 4.7 MEDIUM |
| In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * updateSecondaryStorageSelector * updateHost * updateStorage This issue affects Apache CloudStack: from 4.18.0 before 4.20.2, from 4.21.0 before 4.22.0. Users are recommended to upgrade to versions 4.20.2 or 4.22.0, which contain the fix. The fix introduces a new global configuration flag, js.interpretation.enabled, allowing administrators to control the interpretation of JavaScript expressions in these APIs, thereby mitigating the code injection risk. | |||||
| CVE-2025-59301 | 1 Deltaww | 2 Dvp15mc11t, Dvp15mc11t Firmware | 2026-06-17 | N/A | 4.0 MEDIUM |
| Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service. | |||||
| CVE-2025-59300 | 1 Deltaww | 1 Diascreen | 2026-06-17 | N/A | 7.8 HIGH |
| Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |||||
| CVE-2025-59299 | 1 Deltaww | 1 Diascreen | 2026-06-17 | N/A | 7.8 HIGH |
| Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |||||
| CVE-2025-59298 | 1 Deltaww | 1 Diascreen | 2026-06-17 | N/A | 7.8 HIGH |
| Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |||||
| CVE-2025-59297 | 1 Deltaww | 1 Diascreen | 2026-06-17 | N/A | 7.8 HIGH |
| Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process. | |||||
| CVE-2025-59295 | 1 Microsoft | 16 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 13 more | 2026-06-17 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2025-59294 | 1 Microsoft | 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more | 2026-06-17 | N/A | 2.1 LOW |
| Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | |||||
| CVE-2025-59292 | 1 Microsoft | 1 Azure Compute Gallery | 2026-06-17 | N/A | 8.2 HIGH |
| External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2025-59291 | 1 Microsoft | 1 Azure Compute Gallery | 2026-06-17 | N/A | 8.2 HIGH |
| External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2025-59290 | 1 Microsoft | 8 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 5 more | 2026-06-17 | N/A | 7.8 HIGH |
| Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2025-59289 | 1 Microsoft | 8 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 5 more | 2026-06-17 | N/A | 7.0 HIGH |
| Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2025-59288 | 1 Microsoft | 1 Playwright | 2026-06-17 | N/A | 5.3 MEDIUM |
| Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network. | |||||
| CVE-2025-59287 | 1 Microsoft | 6 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 3 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2025-59286 | 1 Microsoft | 1 365 Copilot Chat | 2026-06-17 | N/A | 9.3 CRITICAL |
| Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2025-59285 | 1 Microsoft | 1 Azure Monitor Agent | 2026-06-17 | N/A | 7.0 HIGH |
| Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |||||
