Total
400509 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-58413 | 1 Fortinet | 2 Fortios, Fortisase | 2026-06-17 | N/A | 7.5 HIGH |
| A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiSASE 25.3.b allows attacker to execute unauthorized code or commands via specially crafted packets | |||||
| CVE-2025-58412 | 1 Fortinet | 1 Fortiadc | 2026-06-17 | N/A | 4.7 MEDIUM |
| A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all versions, FortiADC 7.2 all versions may allow attacker to execute unauthorized code or commands via crafted URL. | |||||
| CVE-2025-58411 | 1 Imaginationtech | 1 Ddk | 2026-06-17 | N/A | 8.8 HIGH |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present. | |||||
| CVE-2025-58410 | 1 Imaginationtech | 1 Ddk | 2026-06-17 | N/A | 7.5 HIGH |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource. | |||||
| CVE-2025-58409 | 1 Imaginationtech | 1 Ddk | 2026-06-17 | N/A | 3.5 LOW |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory. | |||||
| CVE-2025-58408 | 1 Imaginationtech | 1 Ddk | 2026-06-17 | N/A | 5.9 MEDIUM |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use. | |||||
| CVE-2025-58407 | 1 Imaginationtech | 1 Ddk | 2026-06-17 | N/A | 7.4 HIGH |
| Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine. | |||||
| CVE-2025-58406 | 1 Cgm | 1 Clininet | 2026-06-17 | N/A | 4.3 MEDIUM |
| The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls. | |||||
| CVE-2025-58405 | 1 Cgm | 1 Clininet | 2026-06-17 | N/A | 6.1 MEDIUM |
| The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performing unintended actions, including potentially bypassing CSRF/XSRF defenses. | |||||
| CVE-2025-58402 | 1 Cgm | 1 Clininet | 2026-06-17 | N/A | 7.5 HIGH |
| The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users. | |||||
| CVE-2025-58401 | 2026-06-17 | N/A | 6.8 MEDIUM | ||
| Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account. | |||||
| CVE-2025-58400 | 2026-06-17 | N/A | 6.7 MEDIUM | ||
| RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |||||
| CVE-2025-58386 | 1 Terminalfour | 1 Terminalfour | 2026-06-17 | N/A | 9.8 CRITICAL |
| In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged account and escalate its privileges. While manipulating this request, the Power User can also change the target account's password, effectively taking full control of it. | |||||
| CVE-2025-58385 | 1 Doxense | 1 Watchdoc | 2026-06-17 | N/A | 7.1 HIGH |
| In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predictable data). | |||||
| CVE-2025-58384 | 2026-06-17 | N/A | 10.0 CRITICAL | ||
| In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .NET Remoting library in the Watchdoc administration interface. | |||||
| CVE-2025-58383 | 1 Broadcom | 1 Fabric Operating System | 2026-06-17 | N/A | 7.2 HIGH |
| A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary commands. | |||||
| CVE-2025-58382 | 1 Broadcom | 1 Fabric Operating System | 2026-06-17 | N/A | 7.2 HIGH |
| A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command. | |||||
| CVE-2025-58381 | 1 Broadcom | 1 Fabric Operating System | 2026-06-17 | N/A | 2.3 LOW |
| A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories. | |||||
| CVE-2025-58380 | 1 Broadcom | 1 Fabric Operating System | 2026-06-17 | N/A | 2.3 LOW |
| A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories. | |||||
| CVE-2025-58379 | 1 Broadcom | 1 Fabric Operating System | 2026-06-17 | N/A | 5.5 MEDIUM |
| Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user. | |||||
