Vulnerabilities (CVE)

Total 397935 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26157 1 Darkseid 1 Beauty Parlour Management System 2026-06-17 N/A 5.9 MEDIUM
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.
CVE-2025-26156 1 Phpgurukul 1 Online Shopping Portal Project 2026-06-17 N/A 8.8 HIGH
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
CVE-2025-26155 1 Ncp-e 2 Ncp Secure Entry Client, Secure Enterprise Client 2026-06-17 N/A 9.8 CRITICAL
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
CVE-2025-26153 2026-06-17 N/A 5.4 MEDIUM
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
CVE-2025-26138 1 Systemic-rm 1 Risk Value 2026-06-17 N/A 6.5 MEDIUM
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.
CVE-2025-26137 1 Systemic-rm 1 Risk Value 2026-06-17 N/A 7.5 HIGH
Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.
CVE-2025-26136 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.
CVE-2025-26127 2026-06-17 N/A 5.0 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2025-26125 2026-06-17 N/A 7.3 HIGH
An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.
CVE-2025-26091 1 Teampasswordmanager 1 Team Password Manager 2026-06-17 N/A 4.6 MEDIUM
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.
CVE-2025-26086 1 Rsiqueue 1 Management System 2026-06-17 N/A 7.5 HIGH
An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
CVE-2025-26074 2026-06-17 N/A 9.8 CRITICAL
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.
CVE-2025-26065 1 Intelbras 4 Rx 1500, Rx 1500 Firmware, Rx 3000 and 1 more 2026-06-17 N/A 7.3 HIGH
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a visiting Wi-Fi network.
CVE-2025-26064 1 Intelbras 4 Rx 1500, Rx 1500 Firmware, Rx 3000 and 1 more 2026-06-17 N/A 7.3 HIGH
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device.
CVE-2025-26063 1 Intelbras 4 Rx 1500, Rx 1500 Firmware, Rx 3000 and 1 more 2026-06-17 N/A 9.8 CRITICAL
An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.
CVE-2025-26062 1 Intelbras 4 Rx 1500, Rx 1500 Firmware, Rx 3000 and 1 more 2026-06-17 N/A 9.8 CRITICAL
An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.
CVE-2025-26058 1 Webkul 1 Qloapps 2026-06-17 N/A 4.2 MEDIUM
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
CVE-2025-26056 2026-06-17 N/A 5.4 MEDIUM
A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.
CVE-2025-26055 2026-06-17 N/A 6.5 MEDIUM
An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.
CVE-2025-26054 2026-06-17 N/A 5.4 MEDIUM
Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.