Total
398656 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-44177 | 1 Wss | 1 Protop | 2026-06-17 | N/A | 8.2 HIGH |
| A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary files on the underlying OS using encoded traversal sequences. | |||||
| CVE-2025-44176 | 1 Tenda | 2 Fh451, Fh451 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function. | |||||
| CVE-2025-44175 | 1 Tenda | 2 Ac10, Ac10 Firmware | 2026-06-17 | N/A | 5.4 MEDIUM |
| Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function. | |||||
| CVE-2025-44172 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function. | |||||
| CVE-2025-44163 | 1 Raspap | 1 Raspap-webgui | 2026-06-17 | N/A | 6.3 MEDIUM |
| RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution. | |||||
| CVE-2025-44137 | 1 Maptiler | 1 Tileserver Php | 2026-06-17 | N/A | 8.2 HIGH |
| MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read any file on the web server. Affected GET parameters are "TileMatrix", "TileRow", "TileCol" and "Format" | |||||
| CVE-2025-44136 | 1 Maptiler | 1 Tileserver Php | 2026-06-17 | N/A | 9.8 CRITICAL |
| MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser. | |||||
| CVE-2025-44135 | 1 Code-projects | 1 Online Class And Exam Scheduling System | 2026-06-17 | N/A | 6.5 MEDIUM |
| A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks. | |||||
| CVE-2025-44134 | 1 Code-projects | 1 Online Class And Exam Scheduling System | 2026-06-17 | N/A | 6.5 MEDIUM |
| A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks. | |||||
| CVE-2025-44115 | 1 Cotonti | 1 Cotonti Siena | 2026-06-17 | N/A | 5.4 MEDIUM |
| A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting. | |||||
| CVE-2025-44110 | 1 Fluxbb | 1 Fluxbb | 2026-06-17 | N/A | 5.4 MEDIUM |
| FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php. | |||||
| CVE-2025-44109 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages. | |||||
| CVE-2025-44108 | 1 Flatpress | 1 Flatpress | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently. | |||||
| CVE-2025-44091 | 1 Yangyouwang | 1 Crud | 2026-06-17 | N/A | 5.4 MEDIUM |
| yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function. | |||||
| CVE-2025-44084 | 1 Dlink | 2 Di-8100, Di-8100g Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system. | |||||
| CVE-2025-44083 | 1 Dlink | 2 Di-8100, Di-8100 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication | |||||
| CVE-2025-44074 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php. | |||||
| CVE-2025-44073 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. | |||||
| CVE-2025-44072 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php. | |||||
| CVE-2025-44071 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request. | |||||
