Vulnerabilities (CVE)

Total 398591 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-41110 1 Ghostrobotics 2 Vision 60, Vision 60 Firmware 2026-06-17 N/A 8.8 HIGH
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In addition, the attacker can connect via SSH and gain full control of the robot, which could cause physical damage to the robot itself or its environment.
CVE-2025-41109 1 Ghostrobotics 2 Vision 60, Vision 60 Firmware 2026-06-17 N/A 4.6 MEDIUM
Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network connectivity, the robot's internal router automatically assigns IP addresses to any device physically connected to it. An attacker could connect a WiFi access point under their control to gain access to the robot's network without needing the credentials for the deployed network. Once inside, the attacker can monitor all its data, as the robot runs on ROS 2 without authentication by default.
CVE-2025-41108 1 Ghostrobotics 2 Vision 60, Vision 60 Firmware 2026-06-17 N/A 9.8 CRITICAL
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of encryption and authentication mechanisms in the communication protocol allows an attacker to capture legitimate traffic between the robot and the controller, replicate it, and send any valid command to the robot from any attacking computer or device. The communication protocol used in this interface is based on MAVLink, a widely documented protocol, which increases the likelihood of attack. There are two methods for connecting to the robot remotely: Wi-Fi and 4G/LTE.
CVE-2025-41107 1 Qdocs 1 Smart School 2026-06-17 N/A 5.4 MEDIUM
Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her session cookie details.
CVE-2025-41106 1 Fairsketch 1 Rise Ultimate Project Manager 2026-06-17 N/A 5.4 MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'.
CVE-2025-41105 1 Fairsketch 1 Rise Ultimate Project Manager 2026-06-17 N/A 5.4 MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'.
CVE-2025-41104 1 Fairsketch 1 Rise Ultimate Project Manager 2026-06-17 N/A 5.4 MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'.
CVE-2025-41103 1 Fairsketch 1 Rise Ultimate Project Manager 2026-06-17 N/A 5.4 MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'.
CVE-2025-41102 1 Fairsketch 1 Rise Ultimate Project Manager 2026-06-17 N/A 5.4 MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
CVE-2025-41101 1 Fairsketch 1 Rise Ultimate Project Manager 2026-06-17 N/A 5.4 MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'.
CVE-2025-41100 2026-06-17 N/A N/A
Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible to operate the device without the access being logged in the application and even if the access permissions have been revoked.
CVE-2025-41099 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 6.5 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the list of permissions using unauthorised internal identifiers.
CVE-2025-41098 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 7.5 HIGH
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a  misuse of the general enquiry web service.
CVE-2025-41097 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic employee details using unauthorised internal identifiers.
CVE-2025-41096 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers.
CVE-2025-41095 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to planning counter details using unauthorised internal identifiers.
CVE-2025-41094 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers.
CVE-2025-41093 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers.
CVE-2025-41092 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to time records details using unauthorised internal identifiers.
CVE-2025-41091 1 Boldworkplanner 1 Bold Workplanner 2026-06-17 N/A 4.3 MEDIUM
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to calendar details using unauthorised internal identifiers.