Total
398723 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-46685 | 1 Dell | 1 Supportassist Os Recovery | 2026-06-17 | N/A | 7.5 HIGH |
| Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |||||
| CVE-2025-46684 | 1 Dell | 1 Supportassist Os Recovery | 2026-06-17 | N/A | 6.6 MEDIUM |
| Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering. | |||||
| CVE-2025-46676 | 1 Dell | 1 Data Domain Operating System | 2026-06-17 | N/A | 2.7 LOW |
| Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |||||
| CVE-2025-46675 | 1 Nasa | 1 Cryptolib | 2026-06-17 | N/A | 3.5 LOW |
| In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. | |||||
| CVE-2025-46674 | 1 Nasa | 1 Cryptolib | 2026-06-17 | N/A | 3.5 LOW |
| NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle. | |||||
| CVE-2025-46673 | 1 Nasa | 1 Cryptolib | 2026-06-17 | N/A | 4.9 MEDIUM |
| NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS). | |||||
| CVE-2025-46672 | 1 Nasa | 1 Cryptolib | 2026-06-17 | N/A | 3.5 LOW |
| NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. | |||||
| CVE-2025-46661 | 1 Ipwsystems | 1 Metazo | 2026-06-17 | N/A | 10.0 CRITICAL |
| IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have been patched by the Supplier. | |||||
| CVE-2025-46660 | 1 4cstrategies | 1 Exonaut | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt. | |||||
| CVE-2025-46659 | 1 4cstrategies | 1 Exonaut | 2026-06-17 | N/A | 7.5 HIGH |
| An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request. | |||||
| CVE-2025-46658 | 1 4cstrategies | 1 Exonaut | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages. | |||||
| CVE-2025-46657 | 1 Karaz | 1 Karazal | 2026-06-17 | N/A | 7.2 HIGH |
| Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI. | |||||
| CVE-2025-46656 | 1 Matthewwithanm | 1 Markdownify | 2026-06-17 | N/A | 2.9 LOW |
| python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption. | |||||
| CVE-2025-46655 | 2026-06-17 | N/A | 4.9 MEDIUM | ||
| CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but the selected architecture within AWS does not have components that are able to insert Content-Security-Policy headers. | |||||
| CVE-2025-46654 | 1 Hackmd | 1 Codimd | 2026-06-17 | N/A | 4.9 MEDIUM |
| CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file. | |||||
| CVE-2025-46653 | 1 Node-formidable | 1 Formidable | 2026-06-17 | N/A | 3.1 LOW |
| Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content. | |||||
| CVE-2025-46652 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content. | |||||
| CVE-2025-46651 | 1 Prasathmani | 1 Tiny File Manager | 2026-06-17 | N/A | 4.3 MEDIUM |
| Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services. | |||||
| CVE-2025-46647 | 1 Apache | 1 Apisix | 2026-06-17 | N/A | 5.3 MEDIUM |
| A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies only on the issuer being different If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer. This issue affects Apache APISIX: until 3.12.0. Users are recommended to upgrade to version 3.12.0 or higher. | |||||
| CVE-2025-46646 | 1 Artifex | 1 Ghostscript | 2026-06-17 | N/A | 4.5 MEDIUM |
| In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954. | |||||
