Vulnerabilities (CVE)

Total 398723 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-46616 2026-06-17 N/A 9.9 CRITICAL
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
CVE-2025-46614 2026-06-17 N/A 3.3 LOW
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
CVE-2025-46613 2026-06-17 N/A 7.5 HIGH
OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.
CVE-2025-46612 1 Airleader 4 Easy, Easy Firmware, Master Ii\+ and 1 more 2026-06-17 N/A 7.2 HIGH
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.
CVE-2025-46611 1 Artec-it 1 Ema 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.
CVE-2025-46610 1 Artec-it 1 Enterprise Mail Archive 2026-06-17 N/A 8.8 HIGH
ARTEC EMA Mail 6.92 allows CSRF.
CVE-2025-46608 1 Dell 1 Data Lakehouse 2026-06-17 N/A 9.1 CRITICAL
Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity.
CVE-2025-46607 1 Dell 1 Data Domain Operating System 2026-06-17 N/A 6.6 MEDIUM
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
CVE-2025-46606 1 Dell 1 Data Domain Operating System 2026-06-17 N/A 6.2 MEDIUM
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
CVE-2025-46605 1 Dell 1 Data Domain Operating System 2026-06-17 N/A 6.2 MEDIUM
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
CVE-2025-46603 1 Dell 1 Cloudboost Virtual Appliance 2026-06-17 N/A 7.0 HIGH
Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
CVE-2025-46602 1 Dell 1 Supportassist Os Recovery 2026-06-17 N/A 4.4 MEDIUM
Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
CVE-2025-46599 2026-06-17 N/A 6.8 MEDIUM
CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.
CVE-2025-46598 1 Bitcoin 1 Bitcoin Core 2026-06-17 N/A 5.3 MEDIUM
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
CVE-2025-46597 1 Bitcoin 1 Bitcoin Core 2026-06-17 N/A 7.5 HIGH
Bitcoin Core 0.13.0 through 29.x has an integer overflow.
CVE-2025-46595 2026-06-17 N/A 6.4 MEDIUM
An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow crafted HTML to result in Cross Site Scripting. This is mitigated by the fact that an attacker must have a role with permission to create links on the website, for example: create or edit comments or content with a filtered text format.
CVE-2025-46593 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.1 MEDIUM
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-46592 1 Huawei 1 Harmonyos 2026-06-17 N/A 4.4 MEDIUM
Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-46591 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-46590 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.3 MEDIUM
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.