Total
400323 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-57215 | 1 Tenda | 2 Ac10, Ac10 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list_Info. | |||||
| CVE-2025-57213 | 1 Fuyang Lipengjun | 1 Platform | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted request. | |||||
| CVE-2025-57212 | 1 Fuyang Lipengjun | 1 Platform | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted request. | |||||
| CVE-2025-57210 | 1 Fuyang Lipengjun | 1 Platform | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified vectors. | |||||
| CVE-2025-57205 | 1 Inilabs | 1 School Express | 2026-06-17 | N/A | 5.4 MEDIUM |
| iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is saved and later rendered unsanitized, resulting in JavaScript execution in other users' browsers when they access the affected content. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The application does not enforce a restrictive Content Security Policy (CSP) or adequate filtering to prevent such attacks. | |||||
| CVE-2025-57204 | 1 Ui-lib | 1 Stocky | 2026-06-17 | N/A | 5.4 MEDIUM |
| Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulnerability within the Products module available to authenticated users. The vulnerability resides in the product name parameter submitted to the product-creation endpoint via a standard POST form. Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is stored and subsequently rendered unsanitized in downstream views, leading to JavaScript execution in other users' browsers when they access the affected product pages. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially enabling session hijacking, privilege escalation within the application, data exfiltration, or administrative account takeover. The application also lacks a restrictive Content Security Policy (CSP), increasing exploitability. | |||||
| CVE-2025-57203 | 1 Liquidlabs | 1 Magicai | 2026-06-17 | N/A | 4.8 MEDIUM |
| MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feature available to authenticated admin users. The vulnerability resides in the prompt parameter submitted to the /dashboard/user/generator/generate-stream endpoint via a multipart/form-data POST request. Due to insufficient input sanitization, attackers can inject HTML-based JavaScript payloads. This payload is stored and rendered unsanitized in subsequent views, leading to execution in other users' browsers when they access affected content. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The application does not implement a Content Security Policy (CSP) or adequate input filtering to prevent such attacks. A fix should include proper sanitization, output encoding, and strong CSP enforcement to mitigate exploitation. | |||||
| CVE-2025-57176 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. No authentication or path validation is performed. | |||||
| CVE-2025-57164 | 1 Flowiseai | 1 Flowise | 2026-06-17 | N/A | 6.5 MEDIUM |
| Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field. | |||||
| CVE-2025-57156 | 1 Owntone | 1 Owntone Server | 2026-06-17 | N/A | 7.5 HIGH |
| NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash). | |||||
| CVE-2025-57155 | 1 Owntone | 1 Owntone Server | 2026-06-17 | N/A | 7.5 HIGH |
| NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after version 28.2) allows remote attackers to cause a Denial of Service. | |||||
| CVE-2025-57151 | 1 Phpgurukul | 1 Complaint Management System | 2026-06-17 | N/A | 8.8 HIGH |
| phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter. | |||||
| CVE-2025-57150 | 1 Phpgurukul | 1 Complaint Management System | 2026-06-17 | N/A | 7.2 HIGH |
| phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter. | |||||
| CVE-2025-57149 | 1 Phpgurukul | 1 Complaint Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter. | |||||
| CVE-2025-57148 | 1 Phpgurukul | 1 Online Shopping Portal | 2026-06-17 | N/A | 9.1 CRITICAL |
| phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. | |||||
| CVE-2025-57147 | 1 Phpgurukul | 1 Complaint Management System | 2026-06-17 | N/A | 7.5 HIGH |
| A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php. | |||||
| CVE-2025-57146 | 1 Phpgurukul | 1 Complaint Management System | 2026-06-17 | N/A | 8.1 HIGH |
| phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter. | |||||
| CVE-2025-57141 | 1 Ruisitech | 1 Ruisibi | 2026-06-17 | N/A | 9.8 CRITICAL |
| rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc. | |||||
| CVE-2025-57140 | 1 Ruisitech | 1 Ruisibi | 2026-06-17 | N/A | 9.8 CRITICAL |
| rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path. | |||||
| CVE-2025-57118 | 1 Phpgurukul | 1 Online Library Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php | |||||
