Vulnerabilities (CVE)

Total 398251 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29281 1 Perfree 1 Perfreeblog 2026-06-17 N/A 8.8 HIGH
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.
CVE-2025-29280 1 Perfree 1 Perfreeblog 2026-06-17 N/A 4.8 MEDIUM
Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
CVE-2025-29270 2026-06-17 N/A 10.0 CRITICAL
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.
CVE-2025-29266 2026-06-17 N/A 9.6 CRITICAL
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.
CVE-2025-29231 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.
CVE-2025-29230 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 8.6 HIGH
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.
CVE-2025-29229 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
CVE-2025-29228 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 9.8 CRITICAL
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
CVE-2025-29227 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 6.3 MEDIUM
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
CVE-2025-29226 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 6.3 MEDIUM
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.
CVE-2025-29223 1 Linksys 2 E5600, E5600 Firmware 2026-06-17 N/A 6.3 MEDIUM
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.
CVE-2025-29218 1 Tenda 2 W18e, W18e Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2025-29215 1 Tenda 2 Ax12, Ax12 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.
CVE-2025-29214 1 Tenda 2 Ax12, Ax12 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.
CVE-2025-29213 1 Jeewms 1 Jeewms 2026-06-17 N/A 5.5 MEDIUM
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.
CVE-2025-29209 1 Totolink 2 X18, X18 Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.
CVE-2025-29208 1 Codezips 1 Gym Management System 2026-06-17 N/A 6.5 MEDIUM
CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.
CVE-2025-29192 1 Flowiseai 1 Flowise 2026-06-17 N/A 8.2 HIGH
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
CVE-2025-29189 1 Flowiseai 1 Flowise 2026-06-17 N/A 7.6 HIGH
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.
CVE-2025-29181 1 Foxcms 1 Foxcms 2026-06-17 N/A 7.2 HIGH
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.