Vulnerabilities (CVE)

Total 400314 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-56802 1 Reolink 1 Reolink 2026-06-17 N/A 5.1 MEDIUM
The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.
CVE-2025-56801 1 Reolink 1 Reolink 2026-06-17 N/A 5.1 MEDIUM
The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not hardcoded and is instead randomly generated on each installation of the application.
CVE-2025-56800 1 Reolink 1 Reolink 2026-06-17 N/A 5.1 MEDIUM
Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript property(a.settingsManager.lockScreenPassword), an attacker can patch the return value to bypass authentication. NOTE: this is disputed by the Supplier because the lock-screen bypass would only occur if the local user modified his own instance of the application.
CVE-2025-56799 1 Reolink 1 Reolink 2026-06-17 N/A 6.5 MEDIUM
Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.
CVE-2025-56795 1 Mealie 1 Mealie 2026-06-17 N/A 9.0 CRITICAL
Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.
CVE-2025-56769 1 Hutool 1 Hutool 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.
CVE-2025-56764 1 Trivisionsecurity 2 Trivision Nc-227wf, Trivision Nc-227wf Firmware 2026-06-17 N/A 5.3 MEDIUM
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
CVE-2025-56762 1 Paracrawl 1 Keops 2026-06-17 N/A 6.1 MEDIUM
Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.
CVE-2025-56761 1 Usememos 1 Memos 2026-06-17 N/A 5.4 MEDIUM
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their privileges when the stored XSS is viewed by an admin.
CVE-2025-56760 1 Usememos 1 Memos 2026-06-17 N/A 4.3 MEDIUM
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
CVE-2025-56752 1 Ruijie 40 Rg-es205gc, Rg-es205gc-p, Rg-es205gc-p Firmware and 37 more 2026-06-17 N/A 9.4 CRITICAL
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize control of affected devices via crafted HTTP POST request to /user.cgi.
CVE-2025-56749 1 Creativeitem 1 Academy Lms 2026-06-17 N/A 9.4 CRITICAL
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.
CVE-2025-56748 1 Creativeitem 1 Academy Lms 2026-06-17 N/A 6.4 MEDIUM
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.
CVE-2025-56747 1 Creativeitem 1 Academy Lms 2026-06-17 N/A 6.5 MEDIUM
Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions without proper role validation, allowing unauthorized course creation and management.
CVE-2025-56746 1 Creativeitem 1 Academy Lms 2026-06-17 N/A 2.2 LOW
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
CVE-2025-56710 1 Phpgurukul 1 Student Result Management System 2026-06-17 N/A 7.3 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.
CVE-2025-56706 1 Edimax 2 Br-6473ax, Br-6473ax Firmware 2026-06-17 N/A 8.0 HIGH
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.
CVE-2025-56700 2026-06-17 N/A 5.4 MEDIUM
Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user that has access to the platform, to execute arbitrary SQL commands via the datafine parameter.
CVE-2025-56699 2026-06-17 N/A 5.4 MEDIUM
SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.
CVE-2025-56697 1 Askar634 1 Computer Base Test 2026-06-17 N/A 6.1 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php.