Vulnerabilities (CVE)

Total 400356 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-57704 2026-06-17 N/A 5.5 MEDIUM
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.
CVE-2025-57703 1 Deltaww 1 Diaenergie 2026-06-17 N/A 6.1 MEDIUM
DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57702 1 Deltaww 1 Diaenergie 2026-06-17 N/A 6.1 MEDIUM
DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57701 1 Deltaww 1 Diaenergie 2026-06-17 N/A 6.1 MEDIUM
DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57700 1 Deltaww 1 Diaenergie 2026-06-17 N/A 6.1 MEDIUM
DIAEnergie - Stored Cross-site Scripting
CVE-2025-57699 2026-06-17 N/A 6.7 MEDIUM
Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with the SYSTEM privilege.
CVE-2025-57698 1 Astrbot 1 Astrbot 2026-06-17 N/A 7.5 HIGH
AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses the filename to assign to file_path without checking the validity of the filename. The variable file_path is then passed as a parameter to the function `file.save`, so that the file in the request body can be saved to any location in the file system through directory traversal.
CVE-2025-57697 1 Astrbot 1 Astrbot 2026-06-17 N/A 6.5 MEDIUM
AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image_bs64 function defined in entities.py opens the image specified by the user in the request body and returns the image content as a base64-encoded string without checking the legitimacy of the image path, attackers can construct a series of malicious URLs to read any specified file, resulting in sensitive data leakage.
CVE-2025-57692 1 Dotnetfoundation 1 Piranha Cms 2026-06-17 N/A 6.8 MEDIUM
PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser.
CVE-2025-57682 1 Papermark 1 Papermark 2026-06-17 N/A 6.5 MEDIUM
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via the "POST /api/file/s3/get-presigned-get-url-proxy" API
CVE-2025-57681 1 Thestarware 1 Worklogpro 2026-06-17 N/A 5.4 MEDIUM
The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payload placed in an issue's summary field
CVE-2025-57665 1 Element-plus 1 Element-plus 2026-06-17 N/A 6.4 MEDIUM
Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. While native HTML anchor elements present similar risks, UI component libraries bear additional responsibility for implementing security safeguards and providing clear risk documentation. The vulnerability enables XSS attacks, phishing campaigns, and open redirect exploits affecting applications that use Element Plus Link components with user-controlled or untrusted URL inputs.
CVE-2025-57644 1 Accela 1 Automation Platform 2026-06-17 N/A 9.1 CRITICAL
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request forgery (SSRF), enabling interaction with internal or external systems. Successful exploitation can lead to full server compromise, unauthorized access to sensitive data, and further network exploitation.
CVE-2025-57642 1 Sohamjuhin 1 Tourism Management System 2026-06-17 N/A 7.2 HIGH
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.
CVE-2025-57639 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 6.5 MEDIUM
OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.
CVE-2025-57638 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 7.5 HIGH
Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
CVE-2025-57637 1 Dlink 2 Di-7100g, Di-7100g Firmware 2026-06-17 N/A 7.5 HIGH
Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowing attackers to cause a denial of service or execute arbitrary code.
CVE-2025-57636 1 Dlink 2 Di-7100g, Di-7100g Firmware 2026-06-17 N/A 6.5 MEDIUM
OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".
CVE-2025-57633 2026-06-17 N/A 9.8 CRITICAL
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Upload File" action constructs a shell command from the ftp_file parameter and executes it using os.system() without sanitization or escaping.
CVE-2025-57632 2026-06-17 N/A 7.5 HIGH
libsmb2 6.2+ is vulnerable to Buffer Overflow. When processing SMB2 chained PDUs (NextCommand), libsmb2 repeatedly calls smb2_add_iovector() to append to a fixed-size iovec array without checking the upper bound of v->niov (SMB2_MAX_VECTORS=256). An attacker can craft responses with many chained PDUs to overflow v->niov and perform heap out-of-bounds writes, causing memory corruption, crashes, and potentially arbitrary code execution. The SMB2_OPLOCK_BREAK path bypasses message ID validation.