Total
398656 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-44614 | 1 Tinxy | 2 Wifi Lock Controller V1 Rf, Wifi Lock Controller V1 Rf Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext. | |||||
| CVE-2025-44612 | 1 Tinxy | 2 Wifi Lock Controller V1 Rf, Wifi Lock Controller V1 Rf Firmware | 2026-06-17 | N/A | 5.9 MEDIUM |
| Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack. | |||||
| CVE-2025-44595 | 1 Halo | 1 Halo | 2026-06-17 | N/A | 6.1 MEDIUM |
| Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}. | |||||
| CVE-2025-44594 | 1 Halo | 1 Halo | 2026-06-17 | N/A | 9.1 CRITICAL |
| halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. | |||||
| CVE-2025-44593 | 1 Halo | 1 Halo | 2026-06-17 | N/A | 6.1 MEDIUM |
| Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13 | |||||
| CVE-2025-44560 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. | |||||
| CVE-2025-44557 | 2026-06-17 | N/A | 8.1 HIGH | ||
| A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication via a crafted pairing_failed packet. | |||||
| CVE-2025-44206 | 2026-06-17 | N/A | 4.6 MEDIUM | ||
| Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code. | |||||
| CVE-2025-44194 | 1 Oretnom23 | 1 Simple Barangay Management System | 2026-06-17 | N/A | 7.3 HIGH |
| SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household. | |||||
| CVE-2025-44193 | 1 Oretnom23 | 1 Simple Barangay Management System | 2026-06-17 | N/A | 7.6 HIGH |
| SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint. | |||||
| CVE-2025-44192 | 1 Oretnom23 | 1 Simple Barangay Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance. | |||||
| CVE-2025-44186 | 1 Mayurik | 1 Best Employee Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page. | |||||
| CVE-2025-44185 | 1 Mayurik | 1 Best Employee Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter. | |||||
| CVE-2025-44184 | 1 Mayurik | 1 Best Employee Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters. | |||||
| CVE-2025-44183 | 1 Anujk305 | 1 Vehicle Record Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters. | |||||
| CVE-2025-44182 | 1 Anujk305 | 1 Vehicle Record Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum, enginenumber' in the /admin/edit-vehicle.php component. This allows attackers to execute arbitrary code. | |||||
| CVE-2025-44181 | 1 Anujk305 | 1 Vehicle Record Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via the brandname parameter. | |||||
| CVE-2025-44180 | 1 Anujk305 | 1 Vehicle Record Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={brandId}. | |||||
| CVE-2025-44179 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input validation within the telnet command handling mechanism. An attacker can exploit this vulnerability by injecting arbitrary commands through the telnet interface when prompted for inputs or commands. Successful exploitation could lead to remote code execution (RCE) under the privileges of the telnet user, potentially allowing unauthorized access to system settings and sensitive information. | |||||
| CVE-2025-44178 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can exploit this vulnerability to gain unauthorized access to sensitive information and modify its configuration via the UPnP protocol WAN sides without any authentication. | |||||
