Vulnerabilities (CVE)

Total 398160 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-28091 1 Maccms 1 Maccms 2026-06-17 N/A 9.1 CRITICAL
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
CVE-2025-28090 1 Maccms 1 Maccms 2026-06-17 N/A 9.1 CRITICAL
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
CVE-2025-28089 1 Maccms 1 Maccms 2026-06-17 N/A 9.1 CRITICAL
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
CVE-2025-28087 1 Nayem-howlader 1 Online Exam System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.
CVE-2025-28076 2026-06-17 N/A 6.5 MEDIUM
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) timeago, (2) user, (3) filter, (4) target, (5) p1, (6) p2, (7) p3, (8) p4, (9) p5, (10) p6, (11) p7, (12) p8, (13) p9, (14) p10, (15) p11, (16) p12, (17) p13, (18) p14, (19) p15, (20) p16, (21) p17, (22) p18, (23) p19, or (24) p20 parameter to /api/management/updateihmsettings; the (25) ID, (26) NAME, (27) CPUTHREADNB, (28) RAMCAP, or (29) DISKCAP parameter to /api/capaplan/savetemplates.
CVE-2025-28074 1 Phplist 1 Phplist 2026-06-17 N/A 6.1 MEDIUM
phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.
CVE-2025-28073 1 Phplist 1 Phplist 2026-06-17 N/A 6.1 MEDIUM
phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.
CVE-2025-28072 1 Phpgurukul 1 Pre-school Enrollment System 2026-06-17 N/A 7.5 HIGH
PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.
CVE-2025-28062 1 Frappe 1 Erpnext 2026-06-17 N/A 8.1 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
CVE-2025-28059 1 Nagios 1 Network Analyzer 2026-06-17 N/A 7.5 HIGH
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.
CVE-2025-28057 1 Owladmin 1 Owl Admin 2026-06-17 N/A 7.2 HIGH
owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.
CVE-2025-28056 1 Ruifang-tech 1 Rebuild 2026-06-17 N/A 9.8 CRITICAL
rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
CVE-2025-28055 1 Shinnku 1 Upset-gal-web 2026-06-17 N/A 7.5 HIGH
upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit
CVE-2025-28041 1 Liaoxuefeng 1 Itranswarp 2026-06-17 N/A 8.6 HIGH
Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.
CVE-2025-28039 1 Totolink 2 Ex1200t, Ex1200t Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.
CVE-2025-28038 1 Totolink 2 Ex1200t, Ex1200t Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.
CVE-2025-28037 1 Totolink 4 A810r, A810r Firmware, A950rg and 1 more 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.
CVE-2025-28036 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28035 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVE-2025-28034 1 Totolink 12 A3000ru, A3000ru Firmware, A3100r and 9 more 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.