Total
398160 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-28138 | 1 Totolink | 2 A800r, A800r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. | |||||
| CVE-2025-28137 | 1 Totolink | 2 A810r, A810r Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. | |||||
| CVE-2025-28136 | 1 Totolink | 2 A800r, A800r Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi. | |||||
| CVE-2025-28135 | 1 Totolink | 2 A810r, A810r Firmware | 2026-06-17 | N/A | 7.5 HIGH |
| TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi. | |||||
| CVE-2025-28132 | 1 Nagios | 1 Nagios Network Analyzer | 2026-06-17 | N/A | 4.6 MEDIUM |
| A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf. | |||||
| CVE-2025-28131 | 1 Nagios | 1 Network Analyzer | 2026-06-17 | N/A | 4.6 MEDIUM |
| A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability. | |||||
| CVE-2025-28129 | 1 Phpgurukul | 1 Hostel Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. | |||||
| CVE-2025-28128 | 1 Mytel | 1 Telecom Online Account System | 2026-06-17 | N/A | 7.0 HIGH |
| An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request. | |||||
| CVE-2025-28121 | 1 Code-projects | 1 Online Exam Mastering System | 2026-06-17 | N/A | 6.1 MEDIUM |
| code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code. | |||||
| CVE-2025-28104 | 1 Dogukanurker | 1 Flaskblog | 2026-06-17 | N/A | 9.1 CRITICAL |
| Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. | |||||
| CVE-2025-28103 | 1 Dogukanurker | 1 Flaskblog | 2026-06-17 | N/A | 6.4 MEDIUM |
| Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. | |||||
| CVE-2025-28102 | 1 Dogukanurker | 1 Flaskblog | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost. | |||||
| CVE-2025-28101 | 1 Dogukanurker | 1 Flaskblog | 2026-06-17 | N/A | 6.5 MEDIUM |
| An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. | |||||
| CVE-2025-28100 | 1 Geeeeeeeek | 1 Dingfanzu | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. | |||||
| CVE-2025-28099 | 1 Fumiao | 1 Opencms | 2026-06-17 | N/A | 4.3 MEDIUM |
| opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp, | |||||
| CVE-2025-28097 | 1 Onenav | 1 Onenav | 2026-06-17 | N/A | 5.5 MEDIUM |
| OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers. | |||||
| CVE-2025-28096 | 1 Onenav | 1 Onenav | 2026-06-17 | N/A | 5.4 MEDIUM |
| OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers. | |||||
| CVE-2025-28094 | 1 Shopxo | 1 Shopxo | 2026-06-17 | N/A | 6.5 MEDIUM |
| shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places. | |||||
| CVE-2025-28093 | 1 Shopxo | 1 Shopxo | 2026-06-17 | N/A | 6.3 MEDIUM |
| ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings. | |||||
| CVE-2025-28092 | 1 Shopxo | 1 Shopxo | 2026-06-17 | N/A | 6.3 MEDIUM |
| ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. | |||||
