Vulnerabilities (CVE)

Total 398254 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29689 1 Hailey888 1 Oa System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.
CVE-2025-29688 1 Hailey888 1 Oa System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.
CVE-2025-29686 1 Hailey888 1 Oa System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.
CVE-2025-29662 1 Landchat 1 Landchat 2026-06-17 N/A 9.8 CRITICAL
A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.
CVE-2025-29661 1 Litepublisher 1 Litepubl Cms 2026-06-17 N/A 7.2 HIGH
Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
CVE-2025-29660 1 Yiiot 2 Xy-3820, Xy-3820 Firmware 2026-06-17 N/A 9.8 CRITICAL
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques.
CVE-2025-29659 1 Yiiot 2 Xy-3820, Xy-3820 Firmware 2026-06-17 N/A 9.8 CRITICAL
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.
CVE-2025-29647 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CVE-2025-29646 1 Open5gs 1 Open5gs 2026-06-17 N/A 7.1 HIGH
An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).
CVE-2025-29641 1 Anujk305 1 Vehicle Record Management System 2026-06-17 N/A 7.3 HIGH
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.
CVE-2025-29640 1 Anujk305 1 Human Metapneumovirus \(hmpv\) - Testing Management System 2026-06-17 N/A 5.4 MEDIUM
Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter searchdata..
CVE-2025-29635 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 7.2 HIGH
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
CVE-2025-29632 1 Free5gc 1 Free5gc 2026-06-17 N/A 5.4 MEDIUM
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components
CVE-2025-29631 2026-06-17 N/A 9.8 CRITICAL
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute arbitrary operating system commands on a target Home Kit.
CVE-2025-29629 2026-06-17 N/A 9.1 CRITICAL
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.
CVE-2025-29628 2026-06-17 N/A 9.4 CRITICAL
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack. This may result in the attacker capturing device credentials or taking control of vulnerable home kits.
CVE-2025-29627 1 Keepersecurity 1 Keeperchat 2026-06-17 N/A 6.8 MEDIUM
An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module
CVE-2025-29625 1 Astrolog 1 Astrolog 2026-06-17 N/A 7.8 HIGH
A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.
CVE-2025-29621 2026-06-17 N/A 7.3 HIGH
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.
CVE-2025-29606 2026-06-17 N/A 4.3 MEDIUM
py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.