Vulnerabilities (CVE)

Total 398677 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-45019 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the cprice POST request parameter.
CVE-2025-45018 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter.
CVE-2025-45017 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.
CVE-2025-45015 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. The vulnerability allows remote attackers to inject arbitrary JavaScript code via the fromdate and todate parameters.
CVE-2025-45011 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 5.3 MEDIUM
A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.
CVE-2025-45010 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 5.3 MEDIUM
A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.
CVE-2025-45009 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 5.3 MEDIUM
A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata parameter.
CVE-2025-45007 1 Phpgurukul 1 Time Table Generator System 2026-06-17 N/A 4.8 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Generator System v1.0. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the adminname POST request parameter.
CVE-2025-45006 2026-06-17 N/A 9.1 CRITICAL
Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.
CVE-2025-45002 1 Codervivek 1 Vigybag 2026-06-17 N/A 5.4 MEDIUM
Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.
CVE-2025-45001 1 Numan 1 React-native-keys 2026-06-17 N/A 7.5 HIGH
react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
CVE-2025-44998 1 Prasathmani 1 Tiny File Manager 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.
CVE-2025-44963 1 Commscope 1 Ruckus Network Director 2026-06-17 N/A 9.0 CRITICAL
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
CVE-2025-44962 1 Commscope 31 Ruckus C110, Ruckus E510, Ruckus H320 and 28 more 2026-06-17 N/A 5.0 MEDIUM
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
CVE-2025-44961 1 Commscope 31 Ruckus C110, Ruckus E510, Ruckus H320 and 28 more 2026-06-17 N/A 9.9 CRITICAL
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
CVE-2025-44960 1 Commscope 31 Ruckus C110, Ruckus E510, Ruckus H320 and 28 more 2026-06-17 N/A 8.5 HIGH
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
CVE-2025-44958 1 Commscope 1 Ruckus Network Director 2026-06-17 N/A 5.3 MEDIUM
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
CVE-2025-44957 1 Commscope 31 Ruckus C110, Ruckus E510, Ruckus H320 and 28 more 2026-06-17 N/A 8.5 HIGH
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.
CVE-2025-44955 1 Commscope 1 Ruckus Network Director 2026-06-17 N/A 8.8 HIGH
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
CVE-2025-44954 1 Commscope 30 Ruckus C110, Ruckus E510, Ruckus H320 and 27 more 2026-06-17 N/A 9.0 CRITICAL
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.