Vulnerabilities (CVE)

Total 398723 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-46685 1 Dell 1 Supportassist Os Recovery 2026-06-17 N/A 7.5 HIGH
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2025-46684 1 Dell 1 Supportassist Os Recovery 2026-06-17 N/A 6.6 MEDIUM
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.
CVE-2025-46676 1 Dell 1 Data Domain Operating System 2026-06-17 N/A 2.7 LOW
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2025-46675 1 Nasa 1 Cryptolib 2026-06-17 N/A 3.5 LOW
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
CVE-2025-46674 1 Nasa 1 Cryptolib 2026-06-17 N/A 3.5 LOW
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.
CVE-2025-46673 1 Nasa 1 Cryptolib 2026-06-17 N/A 4.9 MEDIUM
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).
CVE-2025-46672 1 Nasa 1 Cryptolib 2026-06-17 N/A 3.5 LOW
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
CVE-2025-46661 1 Ipwsystems 1 Metazo 2026-06-17 N/A 10.0 CRITICAL
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have been patched by the Supplier.
CVE-2025-46660 1 4cstrategies 1 Exonaut 2026-06-17 N/A 5.3 MEDIUM
An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.
CVE-2025-46659 1 4cstrategies 1 Exonaut 2026-06-17 N/A 7.5 HIGH
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.
CVE-2025-46658 1 4cstrategies 1 Exonaut 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.
CVE-2025-46657 1 Karaz 1 Karazal 2026-06-17 N/A 7.2 HIGH
Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.
CVE-2025-46656 1 Matthewwithanm 1 Markdownify 2026-06-17 N/A 2.9 LOW
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.
CVE-2025-46655 2026-06-17 N/A 4.9 MEDIUM
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers.
CVE-2025-46654 1 Hackmd 1 Codimd 2026-06-17 N/A 4.9 MEDIUM
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.
CVE-2025-46653 1 Node-formidable 1 Formidable 2026-06-17 N/A 3.1 LOW
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.
CVE-2025-46652 2026-06-17 N/A 6.1 MEDIUM
In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.
CVE-2025-46651 1 Prasathmani 1 Tiny File Manager 2026-06-17 N/A 4.3 MEDIUM
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.
CVE-2025-46647 1 Apache 1 Apisix 2026-06-17 N/A 5.3 MEDIUM
A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies only on the issuer being different If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer. This issue affects Apache APISIX: until 3.12.0. Users are recommended to upgrade to version 3.12.0 or higher.
CVE-2025-46646 1 Artifex 1 Ghostscript 2026-06-17 N/A 4.5 MEDIUM
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.