Vulnerabilities (CVE)

Total 398252 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29429 1 Fabian 1 Online Class And Exam Scheduling System 2026-06-17 N/A 6.1 MEDIUM
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.
CVE-2025-29427 1 Fabian 1 Online Class And Exam Scheduling System 2026-06-17 N/A 5.9 MEDIUM
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.
CVE-2025-29426 1 Code-projects 1 Online Class And Exam Scheduling System 2026-06-17 N/A 4.6 MEDIUM
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.
CVE-2025-29425 1 Fabian 1 Online Class And Exam Scheduling System 2026-06-17 N/A 5.5 MEDIUM
Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.
CVE-2025-29421 1 Perfree 1 Perfreeblog 2026-06-17 N/A 7.5 HIGH
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
CVE-2025-29420 1 Perfree 1 Perfreeblog 2026-06-17 N/A 7.5 HIGH
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
CVE-2025-29412 1 Martmbithi 1 Ibanking 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
CVE-2025-29411 1 Martmbithi 1 Ibanking 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-29410 1 Kishanlal 1 Hospital Management System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.
CVE-2025-29405 1 Emlog 1 Emlog 2026-06-17 N/A 6.3 MEDIUM
An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-29401 1 Emlog 1 Emlog 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-29394 2026-06-17 N/A 8.1 HIGH
An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.
CVE-2025-29391 1 Horvey 1 Library-manager 2026-06-17 N/A 7.2 HIGH
horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.
CVE-2025-29390 1 Jerryhanjj 1 Erp 2026-06-17 N/A 8.8 HIGH
jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.
CVE-2025-29389 1 Pbootcms 1 Pbootcms 2026-06-17 N/A 6.1 MEDIUM
PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.
CVE-2025-29387 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 7.1 HIGH
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29386 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 9.8 CRITICAL
In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29385 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 9.8 CRITICAL
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29384 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 9.8 CRITICAL
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29369 1 Carmelogarcia 1 Matrimonial Site 2026-06-17 N/A 9.8 CRITICAL
Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.