Total
400314 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-56534 | 1 Opennebula | 1 Opennebula | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2025-56527 | 1 Cinnamon | 1 Kotaemon | 2026-06-17 | N/A | 7.5 HIGH |
| Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage. | |||||
| CVE-2025-56526 | 1 Cinnamon | 1 Kotaemon | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF. | |||||
| CVE-2025-56520 | 1 Dify | 1 Dify | 2026-06-17 | N/A | 5.3 MEDIUM |
| Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720. | |||||
| CVE-2025-56515 | 1 Suisuijiang | 1 Fiora | 2026-06-17 | N/A | 8.8 HIGH |
| File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored. When rendered, these SVG files execute arbitrary JavaScript, enabling attackers to steal user sessions, cookies, and perform unauthorized actions in the context of users viewing affected profiles. | |||||
| CVE-2025-56514 | 1 Suisuijiang | 1 Fiora | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users. | |||||
| CVE-2025-56513 | 1 Nicehash | 1 Quickminer | 2026-06-17 | N/A | 9.8 CRITICAL |
| NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector. NOTE: the Supplier reports that the existence of an http://update.nicehash.com URL is a fabrication, and that there is no other use of HTTP (rather than HTTPS). | |||||
| CVE-2025-56503 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because replacing the uninstall file requires administrator permissions, i.e., there is no privilege escalation. | |||||
| CVE-2025-56498 | 1 Prolink2u | 2 Pgn6401v, Pgn6401v Firmware | 2026-06-17 | N/A | 5.3 MEDIUM |
| An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the /boaform/formPing6 endpoint via the pingAddr parameter, which is not properly sanitized. An authenticated attacker can exploit this flaw by injecting arbitrary system commands, which are executed by the underlying operating system with root privileges. The router uses the Boa web server (version 0.93.15) to handle the request. Successful exploitation can lead to full system compromise and unauthorized control of the network device. | |||||
| CVE-2025-56466 | 1 Masterlifecrm | 1 Dietly | 2026-06-17 | N/A | 7.5 HIGH |
| Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information. | |||||
| CVE-2025-56463 | 1 Mercusys | 2 Mw305r, Mw305r Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure. | |||||
| CVE-2025-56451 | 1 Seeyon | 1 A8\+ Collaborative Management | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint. | |||||
| CVE-2025-56450 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this by sending a specially crafted POST request, resulting in the execution of arbitrary SQL queries. The backend fails to sanitize the user input, allowing enumeration of database schemas, table names, and potentially leading to full database compromise. | |||||
| CVE-2025-56449 | 2026-06-17 | N/A | 8.2 HIGH | ||
| A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the default admin account was found to be locked out via the web interface but still usable through the REST API. This allowed creation of a new privileged user, bypassing MFA protections. This undermines the intended security posture of MFA enforcement. | |||||
| CVE-2025-56448 | 1 Positron | 2 Px360bt, Px360bt Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims. | |||||
| CVE-2025-56435 | 1 Foxcms | 1 Foxcms | 2026-06-17 | N/A | 5.3 MEDIUM |
| SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id. | |||||
| CVE-2025-56431 | 1 Fearlessgeekmedia | 1 Fearlesscms | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function. | |||||
| CVE-2025-56430 | 1 Fearlessgeekmedia | 1 Fearlesscms | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function. | |||||
| CVE-2025-56429 | 1 Fearlessgeekmedia | 1 Fearlesscms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component. | |||||
| CVE-2025-56427 | 1 Composio | 1 Composio | 2026-06-17 | N/A | 7.5 HIGH |
| Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function. | |||||
