Vulnerabilities (CVE)

Total 398160 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-28009 1 Appventure 1 Dietiqa 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.
CVE-2025-27998 2026-06-17 N/A 8.4 HIGH
An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.
CVE-2025-27997 1 Blizzard 1 Battle.net 2026-06-17 N/A 8.4 HIGH
An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.
CVE-2025-27980 1 Oldmoon 1 Cashbook 2026-06-17 N/A 6.5 MEDIUM
cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
CVE-2025-27956 1 Pixeon 1 Weblaudos 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.
CVE-2025-27955 1 Philips 1 Clinical Collaboration Platform 2026-06-17 N/A 6.5 MEDIUM
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.
CVE-2025-27954 1 Philips 1 Clinical Collaboration Platform 2026-06-17 N/A 6.5 MEDIUM
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.
CVE-2025-27953 1 Philips 1 Clinical Collaboration Platform 2026-06-17 N/A 6.5 MEDIUM
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.
CVE-2025-27940 2026-06-17 N/A 4.1 MEDIUM
Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side channel adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
CVE-2025-27939 1 Growatt 1 Cloud Portal 2026-06-17 N/A 7.5 HIGH
An attacker can change registered email addresses of other users and take over arbitrary accounts.
CVE-2025-27938 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
CVE-2025-27937 2026-06-17 N/A 6.5 MEDIUM
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product.
CVE-2025-27936 1 Mattermost 2 Mattermost Server, Ms Teams 2026-06-17 N/A 5.3 MEDIUM
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
CVE-2025-27935 2026-06-17 N/A N/A
The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.
CVE-2025-27934 2026-06-17 N/A 7.5 HIGH
Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product authentication information.
CVE-2025-27933 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 5.4 MEDIUM
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
CVE-2025-27932 2026-06-17 N/A 8.1 HIGH
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an attacker may delete a file on the device or cause a denial of service (DoS) condition.
CVE-2025-27931 1 Pdf-xchange 1 Pdf-xchange Editor 2026-06-17 N/A 6.5 MEDIUM
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
CVE-2025-27930 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.4 MEDIUM
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
CVE-2025-27929 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.