Vulnerabilities (CVE)

Total 400314 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-56534 1 Opennebula 1 Opennebula 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2025-56527 1 Cinnamon 1 Kotaemon 2026-06-17 N/A 7.5 HIGH
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
CVE-2025-56526 1 Cinnamon 1 Kotaemon 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.
CVE-2025-56520 1 Dify 1 Dify 2026-06-17 N/A 5.3 MEDIUM
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.
CVE-2025-56515 1 Suisuijiang 1 Fiora 2026-06-17 N/A 8.8 HIGH
File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored. When rendered, these SVG files execute arbitrary JavaScript, enabling attackers to steal user sessions, cookies, and perform unauthorized actions in the context of users viewing affected profiles.
CVE-2025-56514 1 Suisuijiang 1 Fiora 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users.
CVE-2025-56513 1 Nicehash 1 Quickminer 2026-06-17 N/A 9.8 CRITICAL
NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector. NOTE: the Supplier reports that the existence of an http://update.nicehash.com URL is a fabrication, and that there is no other use of HTTP (rather than HTTPS).
CVE-2025-56503 2026-06-17 N/A 6.5 MEDIUM
An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the uninstall file with a crafted binary in the installation folder. NOTE: this is disputed by the Supplier because replacing the uninstall file requires administrator permissions, i.e., there is no privilege escalation.
CVE-2025-56498 1 Prolink2u 2 Pgn6401v, Pgn6401v Firmware 2026-06-17 N/A 5.3 MEDIUM
An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the /boaform/formPing6 endpoint via the pingAddr parameter, which is not properly sanitized. An authenticated attacker can exploit this flaw by injecting arbitrary system commands, which are executed by the underlying operating system with root privileges. The router uses the Boa web server (version 0.93.15) to handle the request. Successful exploitation can lead to full system compromise and unauthorized control of the network device.
CVE-2025-56466 1 Masterlifecrm 1 Dietly 2026-06-17 N/A 7.5 HIGH
Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.
CVE-2025-56463 1 Mercusys 2 Mw305r, Mw305r Firmware 2026-06-17 N/A 6.8 MEDIUM
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
CVE-2025-56451 1 Seeyon 1 A8\+ Collaborative Management 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.
CVE-2025-56450 2026-06-17 N/A 6.5 MEDIUM
Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this by sending a specially crafted POST request, resulting in the execution of arbitrary SQL queries. The backend fails to sanitize the user input, allowing enumeration of database schemas, table names, and potentially leading to full database compromise.
CVE-2025-56449 2026-06-17 N/A 8.2 HIGH
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the default admin account was found to be locked out via the web interface but still usable through the REST API. This allowed creation of a new privileged user, bypassing MFA protections. This undermines the intended security posture of MFA enforcement.
CVE-2025-56448 1 Positron 2 Px360bt, Px360bt Firmware 2026-06-17 N/A 6.8 MEDIUM
The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.
CVE-2025-56435 1 Foxcms 1 Foxcms 2026-06-17 N/A 5.3 MEDIUM
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id.
CVE-2025-56431 1 Fearlessgeekmedia 1 Fearlesscms 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function.
CVE-2025-56430 1 Fearlessgeekmedia 1 Fearlesscms 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.
CVE-2025-56429 1 Fearlessgeekmedia 1 Fearlesscms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.
CVE-2025-56427 1 Composio 1 Composio 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.