Vulnerabilities (CVE)

Total 398591 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-41351 2026-06-17 N/A N/A
Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.
CVE-2025-41350 1 Iest 1 Winplus 2026-06-17 N/A 5.4 MEDIUM
Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus.svc/json/savesoldoc_post'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
CVE-2025-41349 1 Iest 1 Winplus 2026-06-17 N/A 5.4 MEDIUM
Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus. svc/json/savesolpla_post'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
CVE-2025-41348 1 Iest 1 Winplus 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST request using the parameters 'val1' and 'cont in '/WinplusPortal/ws/sWinplus.svc/json/getacumper_post'.
CVE-2025-41347 1 Iest 1 Winplus 2026-06-17 N/A 9.8 CRITICAL
Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending a POST request to '/WinplusPortal/ws/sWinplus.svc/json/uploadfile'.
CVE-2025-41346 1 Iest 1 Winplus 2026-06-17 N/A 9.8 CRITICAL
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality, integrity, and availability of the data stored in the application.
CVE-2025-41345 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDenunciasById.php'.
CVE-2025-41344 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api/verArchivo.php'.
CVE-2025-41343 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'email' in '/backend/api/users/searchUserByEmail.php'.
CVE-2025-41342 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/buscarUsuarioId.php'.
CVE-2025-41341 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' in '/backend/api/buscarUsuarioByDenuncia.php'.
CVE-2025-41340 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_sociedad' in '/backend/api/buscarTipoDenunciabyId.php'.
CVE-2025-41339 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.
CVE-2025-41338 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'.
CVE-2025-41337 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.
CVE-2025-41336 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros.php'.
CVE-2025-41335 1 Canaldenuncia 1 Canaldenuncia.app 2026-06-17 N/A 7.5 HIGH
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.
CVE-2025-41258 1 Librechat 1 Librechat 2026-06-17 N/A 8.0 HIGH
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
CVE-2025-41257 2026-06-17 N/A 4.8 MEDIUM
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.
CVE-2025-41256 2026-06-17 N/A 7.4 HIGH
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak. This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.