Vulnerabilities (CVE)

Total 398160 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-28138 1 Totolink 2 A800r, A800r Firmware 2026-06-17 N/A 9.8 CRITICAL
The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28137 1 Totolink 2 A810r, A810r Firmware 2026-06-17 N/A 9.8 CRITICAL
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28136 1 Totolink 2 A800r, A800r Firmware 2026-06-17 N/A 6.5 MEDIUM
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
CVE-2025-28135 1 Totolink 2 A810r, A810r Firmware 2026-06-17 N/A 7.5 HIGH
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.
CVE-2025-28132 1 Nagios 1 Nagios Network Analyzer 2026-06-17 N/A 4.6 MEDIUM
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.
CVE-2025-28131 1 Nagios 1 Network Analyzer 2026-06-17 N/A 4.6 MEDIUM
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.
CVE-2025-28129 1 Phpgurukul 1 Hostel Management System 2026-06-17 N/A 5.4 MEDIUM
Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
CVE-2025-28128 1 Mytel 1 Telecom Online Account System 2026-06-17 N/A 7.0 HIGH
An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.
CVE-2025-28121 1 Code-projects 1 Online Exam Mastering System 2026-06-17 N/A 6.1 MEDIUM
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.
CVE-2025-28104 1 Dogukanurker 1 Flaskblog 2026-06-17 N/A 9.1 CRITICAL
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
CVE-2025-28103 1 Dogukanurker 1 Flaskblog 2026-06-17 N/A 6.4 MEDIUM
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
CVE-2025-28102 1 Dogukanurker 1 Flaskblog 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost.
CVE-2025-28101 1 Dogukanurker 1 Flaskblog 2026-06-17 N/A 6.5 MEDIUM
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.
CVE-2025-28100 1 Geeeeeeeek 1 Dingfanzu 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.
CVE-2025-28099 1 Fumiao 1 Opencms 2026-06-17 N/A 4.3 MEDIUM
opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,
CVE-2025-28097 1 Onenav 1 Onenav 2026-06-17 N/A 5.5 MEDIUM
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
CVE-2025-28096 1 Onenav 1 Onenav 2026-06-17 N/A 5.4 MEDIUM
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
CVE-2025-28094 1 Shopxo 1 Shopxo 2026-06-17 N/A 6.5 MEDIUM
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
CVE-2025-28093 1 Shopxo 1 Shopxo 2026-06-17 N/A 6.3 MEDIUM
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
CVE-2025-28092 1 Shopxo 1 Shopxo 2026-06-17 N/A 6.3 MEDIUM
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.