Vulnerabilities (CVE)

Total 398697 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-46229 1 Textmetrics 1 Textmetrics 2026-06-17 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2.
CVE-2025-46228 1 Avecnous 1 Event Post 2026-06-17 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from n/a through <= 5.9.11.
CVE-2025-46227 1 Brechtvds 1 Custom Related Posts 2026-06-17 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: from n/a through <= 1.7.4.
CVE-2025-46226 1 Mpl-publisher 1 Mpl-publisher 2026-06-17 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= 2.18.0.
CVE-2025-46225 1 Migaweb 1 Post In Page For Elementor 2026-06-17 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.
CVE-2025-46215 1 Fortinet 1 Fortisandbox 2026-06-17 N/A 5.3 MEDIUM
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file.
CVE-2025-46205 1 Podofo Project 1 Podofo 2026-06-17 N/A 8.1 HIGH
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.
CVE-2025-46204 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 6.5 MEDIUM
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
CVE-2025-46203 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 6.5 MEDIUM
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
CVE-2025-46199 1 Getgrav 1 Grav 2026-06-17 N/A 9.8 CRITICAL
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields
CVE-2025-46198 1 Getgrav 1 Grav 2026-06-17 N/A 8.8 HIGH
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element
CVE-2025-46193 1 Lerouxyxchire 1 Client Database Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.
CVE-2025-46192 1 Lerouxyxchire 1 Client Database Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.
CVE-2025-46191 1 Lerouxyxchire 1 Client Database Management System 2026-06-17 N/A 9.8 CRITICAL
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication.
CVE-2025-46190 1 Lerouxyxchire 1 Client Database Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.
CVE-2025-46189 1 Lerouxyxchire 1 Client Database Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.
CVE-2025-46188 1 Lerouxyxchire 1 Client Database Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
CVE-2025-46185 2026-06-17 N/A 6.2 MEDIUM
An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.
CVE-2025-46183 2026-06-17 N/A 8.2 HIGH
The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintended code execution or other malicious behavior on the target system.
CVE-2025-46179 1 Vishalmathur 1 Cloudclassroom-php Project 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries.