Total
398677 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-45835 | 1 Netis-systems | 2 Wf2880, Wf2880 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENT_LENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack. | |||||
| CVE-2025-45820 | 1 Slims | 1 Senayan Library Management System Bulian | 2026-06-17 | N/A | 6.5 MEDIUM |
| Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php. | |||||
| CVE-2025-45819 | 1 Slims | 1 Senayan Library Management System Bulian | 2026-06-17 | N/A | 6.5 MEDIUM |
| Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/author.php. | |||||
| CVE-2025-45818 | 1 Slims | 1 Senayan Library Management System Bulian | 2026-06-17 | N/A | 6.5 MEDIUM |
| Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/item_status.php. | |||||
| CVE-2025-45814 | 1 Novelsat | 4 Ns2000, Ns2000 Firmware, Ns3000 and 1 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack. | |||||
| CVE-2025-45813 | 1 Enensys | 2 Ipguardv2, Ipguardv2 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials. | |||||
| CVE-2025-45809 | 1 Litellm | 1 Litellm | 2026-06-17 | N/A | 5.4 MEDIUM |
| SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints. | |||||
| CVE-2025-45806 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2025-45805 | 1 Phpgurukul | 1 Doctor Appointment Management System | 2026-06-17 | N/A | 7.6 HIGH |
| In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment. | |||||
| CVE-2025-45800 | 1 Totolink | 2 A950rg, A950rg Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter. | |||||
| CVE-2025-45798 | 1 Totolink | 2 A950rg, A950rg Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter. | |||||
| CVE-2025-45797 | 1 Totolink | 2 A950rg, A950rg Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so. | |||||
| CVE-2025-45790 | 1 Totolink | 2 A3100r, A3100r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so. | |||||
| CVE-2025-45789 | 1 Totolink | 2 A3100r, A3100r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules. | |||||
| CVE-2025-45788 | 1 Totolink | 2 A3100r, A3100r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules. | |||||
| CVE-2025-45787 | 1 Totolink | 2 A3100r, A3100r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules. | |||||
| CVE-2025-45786 | 1 Updategadh | 1 Real Estate Management | 2026-06-17 | N/A | 8.1 HIGH |
| Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. | |||||
| CVE-2025-45784 | 1 Dlink | 4 Dph-400s, Dph-400s Firmware, Dph-400se and 1 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis tools such as strings or xxd, potentially leading to unauthorized access to device functions or user accounts. This vulnerability exists due to insecure storage of sensitive information in the firmware binary. | |||||
| CVE-2025-45779 | 1 Tenda | 2 Ac10, Ac10 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter. | |||||
| CVE-2025-45778 | 1 Languagesloth | 1 The Language Sloth | 2026-06-17 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description text field. | |||||
