Vulnerabilities (CVE)

Total 397935 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26264 2026-06-17 N/A 8.8 HIGH
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26263 2026-06-17 N/A 5.1 MEDIUM
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
CVE-2025-26262 2026-06-17 N/A 6.5 MEDIUM
An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename.
CVE-2025-26260 1 Plenti 1 Plenti 2026-06-17 N/A 8.8 HIGH
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.
CVE-2025-26258 1 Remyandrade 1 Employee Management System 2026-06-17 N/A 6.1 MEDIUM
Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'
CVE-2025-26211 1 Gibbonedu 1 Gibbon 2026-06-17 N/A 3.7 LOW
Gibbon before 29.0.00 allows CSRF.
CVE-2025-26210 1 Deepseek 3 Deepseek-r1, Deepseek-v2, Deepseek-v3 2026-06-17 N/A 8.8 HIGH
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
CVE-2025-26206 1 Selldone 1 Storefront 2026-06-17 N/A 9.0 CRITICAL
Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
CVE-2025-26202 2026-06-17 N/A 4.3 MEDIUM
Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page
CVE-2025-26200 1 Slims 1 Senayan Library Management System 2026-06-17 N/A 7.2 HIGH
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
CVE-2025-26199 1 Vishalmathur 1 Cloudclassroom-php Project 2026-06-17 N/A 9.8 CRITICAL
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network (e.g., public Wi-Fi or compromised router) can capture login credentials via Man-in-the-Middle (MitM) techniques. If the attacker subsequently uses the credentials to log in and exploit administrative functions (e.g., file upload), this may lead to remote code execution depending on the environment.
CVE-2025-26198 1 Vishalmathur 1 Cloudclassroom-php Project 2026-06-17 N/A 9.8 CRITICAL
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and bypass authentication, gaining unauthorized administrative access. The vulnerability is triggered when an attacker supplies specially crafted input in the username field, such as ' OR '1'='1, leading to complete compromise of the login mechanism and potential exposure of sensitive backend data.
CVE-2025-26186 1 Os4ed 1 Opensis 2026-06-17 N/A 8.1 HIGH
SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php
CVE-2025-26182 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 6.5 MEDIUM
An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file
CVE-2025-26169 2026-06-17 N/A 8.1 HIGH
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.
CVE-2025-26168 2026-06-17 N/A 8.1 HIGH
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.
CVE-2025-26167 2026-06-17 N/A 7.5 HIGH
Buffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web UI and read arbitrary internal files.
CVE-2025-26163 1 Cmsol 1 Auto Atendimento 2026-06-17 N/A 9.8 CRITICAL
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.
CVE-2025-26159 2026-06-17 N/A 6.1 MEDIUM
Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.
CVE-2025-26158 1 Kashipara 1 Online Attendance Management System 2026-06-17 N/A 5.6 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.