Total
398677 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-45316 | 1 Hortusfox | 1 Hortusfox | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter. | |||||
| CVE-2025-45311 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed by multiple parties because the action for a triggered rule can legitimately be an arbitrary operation as root. Thus, the software is behaving in accordance with its intended privilege model. | |||||
| CVE-2025-45286 | 1 Httpbingo | 1 Go-httpbin | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2025-45250 | 1 Mrdoc | 1 Mrdoc | 2026-06-17 | N/A | 5.5 MEDIUM |
| MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file. | |||||
| CVE-2025-45240 | 1 Qianfox | 1 Foxcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php. | |||||
| CVE-2025-45239 | 1 Qianfox | 1 Foxcms | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal. | |||||
| CVE-2025-45238 | 1 Qianfox | 1 Foxcms | 2026-06-17 | N/A | 9.1 CRITICAL |
| foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method. | |||||
| CVE-2025-45237 | 1 Dbsyncer Project | 1 Dbsyncer | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password. | |||||
| CVE-2025-45160 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject arbitrary HTML elements (e.g., <h1>, <b>, <svg>) into the rendered page. NOTE: Multiple third-parties including the maintainer have stated that they cannot reproduce this issue after 1.2.27. | |||||
| CVE-2025-45146 | 1 Codefuse | 1 Modelcache | 2026-06-17 | N/A | 9.8 CRITICAL |
| ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data. | |||||
| CVE-2025-45143 | 1 Devrafalko | 1 String-math | 2026-06-17 | N/A | 7.0 HIGH |
| string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input. | |||||
| CVE-2025-45095 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with write access to the file system could potentially execute arbitrary code with elevated privileges by placing a malicious executable in the unquoted path. | |||||
| CVE-2025-45091 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An authenticated attacker can exploit this vulnerability by modifying their username to include a malicious XSS payload in notification and activities. | |||||
| CVE-2025-45083 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified vectors. | |||||
| CVE-2025-45081 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data. | |||||
| CVE-2025-45065 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint. | |||||
| CVE-2025-45055 | 1 Silverpeas | 1 Silverpeas | 2026-06-17 | N/A | 5.4 MEDIUM |
| Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections. | |||||
| CVE-2025-45042 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function. | |||||
| CVE-2025-45021 | 1 Phpgurukul | 1 Directory Management System | 2026-06-17 | N/A | 5.3 MEDIUM |
| A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands. | |||||
| CVE-2025-45020 | 1 Phpgurukul | 1 Park Ticketing Management System | 2026-06-17 | N/A | 7.2 HIGH |
| A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter in a POST request. | |||||
