Total
398697 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-46229 | 1 Textmetrics | 1 Textmetrics | 2026-06-17 | N/A | 5.9 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2. | |||||
| CVE-2025-46228 | 1 Avecnous | 1 Event Post | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows DOM-Based XSS.This issue affects Event post: from n/a through <= 5.9.11. | |||||
| CVE-2025-46227 | 1 Brechtvds | 1 Custom Related Posts | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: from n/a through <= 1.7.4. | |||||
| CVE-2025-46226 | 1 Mpl-publisher | 1 Mpl-publisher | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher mpl-publisher allows Stored XSS.This issue affects MPL-Publisher: from n/a through <= 2.18.0. | |||||
| CVE-2025-46225 | 1 Migaweb | 1 Post In Page For Elementor | 2026-06-17 | N/A | 6.5 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1. | |||||
| CVE-2025-46215 | 1 Fortinet | 1 Fortisandbox | 2026-06-17 | N/A | 5.3 MEDIUM |
| An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan via a crafted file. | |||||
| CVE-2025-46205 | 1 Podofo Project | 1 Podofo | 2026-06-17 | N/A | 8.1 HIGH |
| A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue. | |||||
| CVE-2025-46204 | 1 Changeweb | 1 Unifiedtransform | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint. | |||||
| CVE-2025-46203 | 1 Changeweb | 1 Unifiedtransform | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint. | |||||
| CVE-2025-46199 | 1 Getgrav | 1 Grav | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields | |||||
| CVE-2025-46198 | 1 Getgrav | 1 Grav | 2026-06-17 | N/A | 8.8 HIGH |
| Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element | |||||
| CVE-2025-46193 | 1 Lerouxyxchire | 1 Client Database Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. | |||||
| CVE-2025-46192 | 1 Lerouxyxchire | 1 Client Database Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter. | |||||
| CVE-2025-46191 | 1 Lerouxyxchire | 1 Client Database Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication. | |||||
| CVE-2025-46190 | 1 Lerouxyxchire | 1 Client Database Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. | |||||
| CVE-2025-46189 | 1 Lerouxyxchire | 1 Client Database Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. | |||||
| CVE-2025-46188 | 1 Lerouxyxchire | 1 Client Database Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. | |||||
| CVE-2025-46185 | 2026-06-17 | N/A | 6.2 MEDIUM | ||
| An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames. | |||||
| CVE-2025-46183 | 2026-06-17 | N/A | 8.2 HIGH | ||
| The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintended code execution or other malicious behavior on the target system. | |||||
| CVE-2025-46179 | 1 Vishalmathur | 1 Cloudclassroom-php Project | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries. | |||||
