Total
400314 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-56332 | 1 Pangolin | 1 Pangolin | 2026-06-17 | N/A | 9.1 CRITICAL |
| Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default Configuration | |||||
| CVE-2025-56316 | 1 Mingsoft | 1 Mcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering. | |||||
| CVE-2025-56313 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary JavaScript in a user's web browser by including a malicious payload in the "code" URL parameter. When an authenticated admin user accesses the study's URL, the malicious script gets interpreted and executes within their browser, which can lead to unauthorized actions, account compromise, and privilege escalation. | |||||
| CVE-2025-56311 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can craft a malicious webpage that, when visited by an authenticated administrator, causes the router to reboot without explicit user consent. This lack of CSRF protection on a sensitive administrative function can lead to denial of service by disrupting network availability. | |||||
| CVE-2025-56301 | 1 Chipsalliance | 1 Rocket-chip | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowing attackers to corrupt exception handling and privilege state transitions via a flawed interaction between exception handling and MRET return mechanisms in the CSR logic when an exception is triggered during MRET execution. The Control and Status Register (CSR) logic has a flawed interaction between exception handling and exception return (MRET) mechanisms which can cause faulty trap behavior. When the MRET instruction is executed in machine mode without being in an exception state, an Instruction Access Fault may be triggered. This results in both the exception handling logic and the exception return logic activating simultaneously, leading to conflicting updates to the control and status registers. | |||||
| CVE-2025-56280 | 1 Carmelo | 1 Food Ordering Review System | 2026-06-17 | N/A | 5.4 MEDIUM |
| code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information. | |||||
| CVE-2025-56276 | 1 Carmelo | 1 Food Ordering Review System | 2026-06-17 | N/A | 5.4 MEDIUM |
| code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the disclosure of the admin's cookie information. | |||||
| CVE-2025-56267 | 1 Avigilon | 1 Access Control Manager | 2026-06-17 | N/A | 9.8 CRITICAL |
| A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file. | |||||
| CVE-2025-56266 | 1 Avigilon | 1 Access Control Manager | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL. | |||||
| CVE-2025-56265 | 1 N8n | 1 N8n | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file. | |||||
| CVE-2025-56264 | 1 Zhyd | 1 Oneblog | 2026-06-17 | N/A | 7.5 HIGH |
| The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability. | |||||
| CVE-2025-56263 | 1 By-night | 1 Sms | 2026-06-17 | N/A | 8.8 HIGH |
| by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of any size and type. | |||||
| CVE-2025-56254 | 1 Phpgurukul | 1 Employee Leave Management System | 2026-06-17 | N/A | 4.3 MEDIUM |
| PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users. | |||||
| CVE-2025-56252 | 1 Pathinfotech | 1 Servitiumcrm | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted URL to the mobile parameter. | |||||
| CVE-2025-56243 | 1 Puneethreddyhc | 1 Event Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System 1.0, where the event_id GET parameter is improperly handled. An attacker can craft a malicious URL to execute arbitrary JavaScript in the victim s browser by injecting code into this parameter. | |||||
| CVE-2025-56241 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication. | |||||
| CVE-2025-56234 | 2026-06-17 | N/A | 7.5 HIGH | ||
| AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA2000 has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be within the current receive window, which violates RFC5961. This flaw allows attackers to send multiple random TCP RST packets to hit the acceptable range of sequence numbers, thereby interrupting normal connections and causing a denial-of-service attack. | |||||
| CVE-2025-56233 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be within the current receive window, which violates RFC5961. This flaw allows attackers to send multiple random TCP RST/SYN packets to hit the acceptable range of sequence numbers, thereby interrupting normal connections and causing a denial of service attack. | |||||
| CVE-2025-56232 | 1 Cdprojekt | 1 Gog Galaxy | 2026-06-17 | N/A | 6.8 MEDIUM |
| GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files. | |||||
| CVE-2025-56230 | 1 Tencent | 1 Docs | 2026-06-17 | N/A | 7.5 HIGH |
| Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component. | |||||
