Vulnerabilities (CVE)

Total 398483 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-36750 1 Growatt 2 Shine Lan-x, Shine Lan-x Firmware 2026-06-17 N/A 5.4 MEDIUM
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
CVE-2025-36748 1 Growatt 2 Shine Lan-x, Shine Lan-x Firmware 2026-06-17 N/A 5.4 MEDIUM
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScript code snippet can be inserted in the communication module’s settings center. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
CVE-2025-36747 1 Growatt 2 Shine Lan-x, Shine Lan-x Firmware 2026-06-17 N/A 9.8 CRITICAL
ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection with the server. This may allow an attacker to replace legitimate files being deployed to devices with their own malicious versions, since the firmware signature verification is not enforced.
CVE-2025-36746 1 Solaredge 1 Solaredge Monitoring Platform 2026-06-17 N/A 5.4 MEDIUM
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
CVE-2025-36745 1 Solaredge 2 Se3680h, Se3680h Firmware 2026-06-17 N/A 7.8 HIGH
SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.
CVE-2025-36744 1 Solaredge 2 Se3680h, Se3680h Firmware 2026-06-17 N/A 2.4 LOW
SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.
CVE-2025-36743 1 Solaredge 2 Se3680h, Se3680h Firmware 2026-06-17 N/A 6.8 MEDIUM
SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of system internals and execution of debug commands.
CVE-2025-36730 2026-06-17 N/A N/A
A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions.
CVE-2025-36729 2026-06-17 N/A 7.2 HIGH
A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.
CVE-2025-36728 1 Simple-help 1 Simplehelp 2026-06-17 N/A 6.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.
CVE-2025-36727 1 Simple-help 1 Simplehelp 2026-06-17 N/A 8.3 HIGH
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.
CVE-2025-36640 2026-06-17 N/A 8.8 HIGH
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges.
CVE-2025-36636 2026-06-17 N/A 4.3 MEDIUM
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
CVE-2025-36633 2 Microsoft, Tenable 2 Windows, Nessus Agent 2026-06-17 N/A 8.8 HIGH
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.
CVE-2025-36632 2 Microsoft, Tenable 2 Windows, Nessus Agent 2026-06-17 N/A 7.8 HIGH
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
CVE-2025-36631 2 Microsoft, Tenable 2 Windows, Nessus Agent 2026-06-17 N/A 8.4 HIGH
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
CVE-2025-36630 2 Microsoft, Tenable 2 Windows, Nessus 2026-06-17 N/A 8.4 HIGH
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.
CVE-2025-36625 2026-06-17 N/A 4.3 MEDIUM
In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.
CVE-2025-36613 1 Dell 2 Supportassist For Business Pcs, Supportassist For Home Pcs 2026-06-17 N/A 2.8 LOW
SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
CVE-2025-36612 1 Dell 1 Supportassist For Business Pcs 2026-06-17 N/A 6.7 MEDIUM
SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.