Vulnerabilities (CVE)

Total 398252 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29477 1 Treasuredata 1 Fluent Bit 2026-06-17 N/A 5.5 MEDIUM
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
CVE-2025-29476 2026-06-17 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.
CVE-2025-29471 1 Nagios 1 Log Server 2026-06-17 N/A 8.3 HIGH
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
CVE-2025-29462 1 Tenda 2 Ac15, Ac15 Firmware 2026-06-17 N/A 9.8 CRITICAL
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.
CVE-2025-29461 1 Appleple 1 A-blogcms 2026-06-17 N/A 7.6 HIGH
An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.
CVE-2025-29460 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29459 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29458 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29457 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29456 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.
CVE-2025-29455 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
CVE-2025-29454 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
CVE-2025-29453 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.
CVE-2025-29452 1 Seopanel 1 Seo Panel 2026-06-17 N/A 7.6 HIGH
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
CVE-2025-29451 1 Seopanel 1 Seo Panel 2026-06-17 N/A 7.6 HIGH
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
CVE-2025-29450 1 Lm21 1 Twonav 2026-06-17 N/A 6.5 MEDIUM
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.
CVE-2025-29449 1 Lm21 1 Twonav 2026-06-17 N/A 6.5 MEDIUM
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.
CVE-2025-29448 1 Easyappointments 1 Easy\!appointments 2026-06-17 N/A 7.5 HIGH
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.
CVE-2025-29431 1 Code-projects 1 Online Class And Exam Scheduling System 2026-06-17 N/A 3.2 LOW
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.
CVE-2025-29430 1 Fabian 1 Online Class And Exam Scheduling System 2026-06-17 N/A 4.1 MEDIUM
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.