Vulnerabilities (CVE)

Total 398833 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48018 2026-06-17 N/A 7.5 HIGH
An authenticated user can modify application state data.
CVE-2025-48017 2026-06-17 N/A 9.0 CRITICAL
Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files
CVE-2025-48016 2026-06-17 N/A 4.3 MEDIUM
OpenFlow discovery protocol can exhaust resources because it is not rate limited
CVE-2025-48015 2026-06-17 N/A 3.7 LOW
Failed login response could be different depending on whether the username was local or central.
CVE-2025-48014 2026-06-17 N/A 7.5 HIGH
Password guessing limits could be bypassed when using LDAP authentication.
CVE-2025-48013 1 Quick Node Block Project 1 Quick Node Block 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.
CVE-2025-48012 1 One Time Password Project 1 One Time Password 2026-06-17 N/A 4.8 MEDIUM
Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.
CVE-2025-48011 1 One Time Password Project 1 One Time Password 2026-06-17 N/A 4.8 MEDIUM
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
CVE-2025-48010 1 One Time Password Project 1 One Time Password 2026-06-17 N/A 4.8 MEDIUM
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
CVE-2025-48009 1 Single Content Sync Project 1 Single Content Sync 2026-06-17 N/A 3.1 LOW
Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.
CVE-2025-48008 1 F5 23 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 20 more 2026-06-17 N/A 7.5 HIGH
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-48007 1 Hallowelt 1 Bluespice 2026-06-17 N/A 6.4 MEDIUM
Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.
CVE-2025-48006 1 Saison 1 Dataspider Servista 2026-06-17 N/A 9.1 CRITICAL
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.
CVE-2025-48005 1 Libbiosig Project 1 Libbiosig 2026-06-17 N/A 9.8 CRITICAL
A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2025-48004 1 Microsoft 6 Windows 11 22h2, Windows 11 23h2, Windows 11 24h2 and 3 more 2026-06-17 N/A 7.4 HIGH
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2025-48003 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-06-17 N/A 6.8 MEDIUM
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2025-48002 1 Microsoft 2 Windows 11 24h2, Windows Server 2025 2026-06-17 N/A 5.7 MEDIUM
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.
CVE-2025-48001 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2026-06-17 N/A 6.8 MEDIUM
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2025-48000 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-06-17 N/A 7.8 HIGH
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47999 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-06-17 N/A 6.8 MEDIUM
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.