Vulnerabilities (CVE)

Total 398020 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26846 1 Znuny 1 Znuny 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.
CVE-2025-26845 1 Znuny 1 Znuny 2026-06-17 N/A 9.8 CRITICAL
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
CVE-2025-26844 1 Znuny 1 Znuny 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
CVE-2025-26842 1 Znuny 1 Znuny 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.
CVE-2025-26841 1 Wpeverest 1 Everest Forms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.
CVE-2025-26819 1 Getmonero 1 Monero 2026-06-17 N/A 8.6 HIGH
Monero through 0.18.3.4 before ec74ff4 does not have response limits on HTTP server connections.
CVE-2025-26818 1 Netwrix 1 Password Secure 2026-06-17 N/A 9.8 CRITICAL
Netwrix Password Secure through 9.2 allows command injection.
CVE-2025-26817 1 Netwrix 1 Password Secure 2026-06-17 N/A 9.8 CRITICAL
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
CVE-2025-26816 2026-06-17 N/A 6.5 MEDIUM
A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.
CVE-2025-26803 1 Phusion 1 Passenger 2026-06-17 N/A 5.3 MEDIUM
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
CVE-2025-26796 1 Apache 1 Oozie 2026-06-17 N/A 5.4 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-26795 1 Apache 1 Iotdb 2026-06-17 N/A 7.5 HIGH
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
CVE-2025-26794 1 Exim 1 Exim 2026-06-17 N/A 7.5 HIGH
Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)
CVE-2025-26793 2026-06-17 N/A N/A
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password."
CVE-2025-26791 1 Cure53 1 Dompurify 2026-06-17 N/A 4.5 MEDIUM
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CVE-2025-26789 2026-06-17 N/A N/A
An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Manager in a Logpoint deployment.
CVE-2025-26788 2026-06-17 N/A 8.4 HIGH
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
CVE-2025-26787 1 Keyfactor 1 Signserver 2026-06-17 N/A 4.7 MEDIUM
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certificate to connect. Admins can then set more restricted access to specific certificates. A logic error caused this admin CLI command to be run on each restart of the container instead of only the first startup as intended resetting the configuration to "allowany".
CVE-2025-26785 1 Samsung 34 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 31 more 2026-06-17 N/A 7.5 HIGH
An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.
CVE-2025-26784 1 Samsung 34 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 31 more 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.