Total
398251 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-29281 | 1 Perfree | 1 Perfreeblog | 2026-06-17 | N/A | 8.8 HIGH |
| In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them. | |||||
| CVE-2025-29280 | 1 Perfree | 1 Perfreeblog | 2026-06-17 | N/A | 4.8 MEDIUM |
| Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code. | |||||
| CVE-2025-29270 | 2026-06-17 | N/A | 10.0 CRITICAL | ||
| Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device. | |||||
| CVE-2025-29266 | 2026-06-17 | N/A | 9.6 CRITICAL | ||
| Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled. | |||||
| CVE-2025-29231 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters. | |||||
| CVE-2025-29230 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 8.6 HIGH |
| Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter. | |||||
| CVE-2025-29229 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. | |||||
| CVE-2025-29228 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. | |||||
| CVE-2025-29227 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 6.3 MEDIUM |
| In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter. | |||||
| CVE-2025-29226 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 6.3 MEDIUM |
| In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter. | |||||
| CVE-2025-29223 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 6.3 MEDIUM |
| Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function. | |||||
| CVE-2025-29218 | 1 Tenda | 2 W18e, W18e Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |||||
| CVE-2025-29215 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList. | |||||
| CVE-2025-29214 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg. | |||||
| CVE-2025-29213 | 1 Jeewms | 1 Jeewms | 2026-06-17 | N/A | 5.5 MEDIUM |
| A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file. | |||||
| CVE-2025-29209 | 1 Totolink | 2 X18, X18 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi. | |||||
| CVE-2025-29208 | 1 Codezips | 1 Gym Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php. | |||||
| CVE-2025-29192 | 1 Flowiseai | 1 Flowise | 2026-06-17 | N/A | 8.2 HIGH |
| Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log. | |||||
| CVE-2025-29189 | 1 Flowiseai | 1 Flowise | 2026-06-17 | N/A | 7.6 HIGH |
| Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores. | |||||
| CVE-2025-29181 | 1 Foxcms | 1 Foxcms | 2026-06-17 | N/A | 7.2 HIGH |
| FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php. | |||||
