Total
398697 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-46109 | 1 Pbootcms | 1 Pbootcms | 2026-06-17 | N/A | 8.8 HIGH |
| SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request | |||||
| CVE-2025-46108 | 1 Dlink | 2 Dir-513, Dir-513 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup. | |||||
| CVE-2025-46101 | 1 Beakon | 1 Learning Management System Sharable Content Object Reference Model | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file | |||||
| CVE-2025-46096 | 1 Noear | 1 Solon | 2026-06-17 | N/A | 6.1 MEDIUM |
| Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component | |||||
| CVE-2025-46094 | 1 Liquidfiles | 1 Liquidfiles | 2026-06-17 | N/A | 3.8 LOW |
| LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript. | |||||
| CVE-2025-46093 | 1 Liquidfiles | 1 Liquidfiles | 2026-06-17 | N/A | 9.9 CRITICAL |
| LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration. | |||||
| CVE-2025-46080 | 1 Huocms | 1 Huocms | 2026-06-17 | N/A | 5.3 MEDIUM |
| HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server. | |||||
| CVE-2025-46078 | 1 Huocms | 1 Huocms | 2026-06-17 | N/A | 5.3 MEDIUM |
| HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server | |||||
| CVE-2025-46070 | 1 Automai | 1 Botmanager | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component | |||||
| CVE-2025-46068 | 1 Automai | 1 Director | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism | |||||
| CVE-2025-46067 | 1 Automai | 1 Director | 2026-06-17 | N/A | 8.2 HIGH |
| An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file | |||||
| CVE-2025-46066 | 1 Automai | 1 Director | 2026-06-17 | N/A | 9.9 CRITICAL |
| An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges | |||||
| CVE-2025-46059 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the Supplier because the code-execution issue was introduced by user-written code that does not adhere to the LangChain security practices. | |||||
| CVE-2025-46053 | 1 Weberp | 1 Weberp | 2026-06-17 | N/A | 5.1 MEDIUM |
| A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php | |||||
| CVE-2025-46052 | 1 Weberp | 1 Weberp | 2026-06-17 | N/A | 9.8 CRITICAL |
| An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into the DEL form field in a POST request to /StockCounts.php | |||||
| CVE-2025-46047 | 1 Silverpeas | 1 Silverpeas | 2026-06-17 | N/A | 6.5 MEDIUM |
| A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter. | |||||
| CVE-2025-46018 | 1 Cscsw | 1 Pay Mobile | 2026-06-17 | N/A | 5.4 MEDIUM |
| CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss. | |||||
| CVE-2025-46014 | 1 Honor | 1 Pc Manager | 2026-06-17 | N/A | 8.8 HIGH |
| Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation. | |||||
| CVE-2025-46011 | 1 Nadh | 1 Listmonk | 2026-06-17 | N/A | 6.5 MEDIUM |
| Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges. | |||||
| CVE-2025-46002 | 1 Simogeo | 1 Filemanager | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint. | |||||
