Vulnerabilities (CVE)

Total 398254 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29602 1 Flatpress 1 Flatpress 2026-06-17 N/A 6.1 MEDIUM
flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.
CVE-2025-29594 2026-06-17 N/A 6.1 MEDIUM
A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.
CVE-2025-29592 1 Aaluoxiang 1 Oa System 2026-06-17 N/A 5.6 MEDIUM
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
CVE-2025-29573 1 Jupo 1 Mezzanine 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.
CVE-2025-29570 1 Szlbt 2 Lbt-t300-t400, Lbt-t300-t400 Firmware 2026-06-17 N/A 7.8 HIGH
An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named rc.
CVE-2025-29568 1 Code-projects 1 Online Class And Exam Scheduling System 2026-06-17 N/A 4.8 MEDIUM
A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS).
CVE-2025-29557 2026-06-17 N/A 5.4 MEDIUM
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
CVE-2025-29556 2026-06-17 N/A 7.3 HIGH
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw in the account creation process allows an attacker to bypass these restrictions via API request manipulation. An attacker with an Admin access can intercept and modify the API request during user creation, altering the parameters to assign the new account to the ExaGrid Security Officers group without the required approval.
CVE-2025-29547 1 Horizondatasys 1 Rollback Rx Pro 2026-06-17 N/A 7.0 HIGH
In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.
CVE-2025-29529 2026-06-17 N/A 6.5 MEDIUM
ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.
CVE-2025-29526 2026-06-17 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.
CVE-2025-29525 2026-06-17 N/A 5.3 MEDIUM
DASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was discovered to contain insecure default credentials in the modem's control panel.
CVE-2025-29524 2026-06-17 N/A 6.5 MEDIUM
Incorrect access control in the component /cgi-bin/system_diagnostic_main.asp of DASAN GPON ONU H660WM H660WMR210825 allows attackers to access sensitive information.
CVE-2025-29523 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 7.2 HIGH
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.
CVE-2025-29522 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.
CVE-2025-29521 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 5.3 MEDIUM
Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack.
CVE-2025-29520 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 5.3 MEDIUM
Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account passwords and escalate privileges.
CVE-2025-29519 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 5.3 MEDIUM
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.
CVE-2025-29517 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 6.8 MEDIUM
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.
CVE-2025-29516 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 7.2 HIGH
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function.