Vulnerabilities (CVE)

Total 398235 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29043 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
CVE-2025-29042 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c
CVE-2025-29041 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c
CVE-2025-29040 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
CVE-2025-29039 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 7.2 HIGH
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
CVE-2025-29036 2026-06-17 N/A 5.9 MEDIUM
An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.
CVE-2025-29033 2026-06-17 N/A 7.3 HIGH
An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.
CVE-2025-29032 1 Tendacn 2 Ac9, Ac9 Firmware 2026-06-17 N/A 5.9 MEDIUM
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2025-29031 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
CVE-2025-29030 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2025-29029 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
CVE-2025-29018 1 Codeastro 1 Internet Banking System 2026-06-17 N/A 4.8 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.
CVE-2025-29017 1 Codeastro 1 Internet Banking System 2026-06-17 N/A 8.8 HIGH
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
CVE-2025-29015 1 Codeastro 1 Internet Banking System 2026-06-17 N/A 6.1 MEDIUM
Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
CVE-2025-29014 2026-06-17 N/A 7.1 HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu allows Reflected XSS. This issue affects FoodMenu: from n/a through 1.20.
CVE-2025-29013 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in faaiq Custom Category/Post Type Post order custom-post-order-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Category/Post Type Post order: from n/a through <= 1.6.0.
CVE-2025-29012 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 7 Mailchimp Add-on: from n/a through < 2.4.
CVE-2025-29011 2026-06-17 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer YouTube Simple Gallery youtube-simple-gallery allows Stored XSS.This issue affects YouTube Simple Gallery: from n/a through <= 2.2.0.
CVE-2025-29010 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.
CVE-2025-29009 2026-06-17 N/A 10.0 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through <= 1.2.3.