Vulnerabilities (CVE)

Total 398235 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29094 1 Motivian 1 Content Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components.
CVE-2025-29093 1 Motivian 1 Content Management System 2026-06-17 N/A 8.2 HIGH
File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component.
CVE-2025-29089 2026-06-17 N/A 7.5 HIGH
An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information
CVE-2025-29088 1 Sqlite 1 Sqlite 2026-06-17 N/A 5.6 MEDIUM
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.
CVE-2025-29087 1 Sqlite 1 Sqlite 2026-06-17 N/A 3.2 LOW
In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.
CVE-2025-29085 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
CVE-2025-29084 1 Cszcms 1 Csz Cms 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgrade.php file.
CVE-2025-29083 1 Cszcms 1 Csz Cms 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin_Manager.php file.
CVE-2025-29072 1 Nethermind 1 Juno 2026-06-17 N/A 7.5 HIGH
An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.
CVE-2025-29070 2026-06-17 N/A 7.5 HIGH
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."
CVE-2025-29069 2026-06-17 N/A 7.3 HIGH
A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier because the finding identified a bug in a third-party calling program, not in lcms.
CVE-2025-29064 1 Totolink 2 X18, X18 Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.
CVE-2025-29063 1 Lb-link 2 Bl-ac2100, Bl-ac2100 Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
CVE-2025-29062 1 Lb-link 2 Bl-ac2100, Bl-ac2100 Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
CVE-2025-29058 1 Qimou Cms Project 1 Qimou Cms 2026-06-17 N/A 9.8 CRITICAL
An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.
CVE-2025-29049 2026-06-17 N/A 6.3 MEDIUM
Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.
CVE-2025-29047 1 Alfa 2 Wifi Camppro, Wifi Camppro Firmware 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddenIndex in the function StorageEditUser
CVE-2025-29046 1 Alfa 2 Wifi Camppro, Wifi Camppro Firmware 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value
CVE-2025-29045 1 Alfa 2 Wifi Camppro, Wifi Camppro Firmware 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value
CVE-2025-29044 1 Netgear 2 R6100, R6100 Firmware 2026-06-17 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key value