Vulnerabilities (CVE)

Total 398677 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-45526 2026-06-17 N/A 2.9 LOW
A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This library, used for syntax highlighting, does not limit the size of textual content it processes in HTML elements with the microlight class. When excessively large content (e.g., 100 million characters) is processed, the reset function in microlight.js consumes excessive memory and CPU resources, causing browser crashes or unresponsiveness. An attacker can exploit this vulnerability by tricking a user into visiting a malicious web page containing a microlight element with large content, resulting in a denial of service. NOTE: this is disputed by multiple parties because a large amount of memory and CPU resources is expected to be needed for content of that size.
CVE-2025-45525 2026-06-17 N/A 2.9 LOW
A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a lightweight syntax highlighting library. When processing elements with non-standard CSS color values, the library fails to validate the result of a regular expression match before accessing its properties, leading to an uncaught TypeError and potential application crash. NOTE: this is disputed by multiple parties because there is no common scenario in which an adversary can insert those non-standard values.
CVE-2025-45514 1 Tenda 2 Fh451, Fh451 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.
CVE-2025-45513 1 Tenda 2 Fh451, Fh451 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.
CVE-2025-45512 1 Denx 1 U-boot 2026-06-17 N/A 6.5 MEDIUM
A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.
CVE-2025-45493 1 Netgear 2 Ex8000, Ex8000 Firmware 2026-06-17 N/A 6.5 MEDIUM
Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.
CVE-2025-45492 1 Netgear 2 Ex8000, Ex8000 Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.
CVE-2025-45491 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
CVE-2025-45490 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
CVE-2025-45489 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
CVE-2025-45488 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
CVE-2025-45487 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
CVE-2025-45479 1 Educoder 1 Challenges 2026-06-17 N/A 9.8 CRITICAL
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.
CVE-2025-45475 1 Maccms 1 Maccms 2026-06-17 N/A 5.4 MEDIUM
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
CVE-2025-45474 1 Maccms 1 Maccms 2026-06-17 N/A 7.3 HIGH
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
CVE-2025-45472 1 Lumigo 1 Autodeploy-layer 2026-06-17 N/A 8.8 HIGH
Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.
CVE-2025-45471 1 Lumigo 1 Measure-cold-start 2026-06-17 N/A 8.8 HIGH
Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.
CVE-2025-45468 1 Devsapp 1 Fc-stable-diffusion 2026-06-17 N/A 8.8 HIGH
Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.
CVE-2025-45467 1 Unitree 2 Go1, Go1 Firmware 2026-06-17 N/A 7.1 HIGH
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.
CVE-2025-45466 1 Unitree 2 Go1, Go1 Firmware 2026-06-17 N/A 8.8 HIGH
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.