Vulnerabilities (CVE)

Total 397935 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26047 1 Olajowon 1 Loggrove 2026-06-17 N/A 5.1 MEDIUM
Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
CVE-2025-26042 2026-06-17 N/A 6.0 MEDIUM
Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.
CVE-2025-26014 1 Olajowon 1 Loggrove 2026-06-17 N/A 9.8 CRITICAL
A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.
CVE-2025-26013 1 Olajowon 1 Loggrove 2026-06-17 N/A 8.2 HIGH
An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
CVE-2025-26011 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.
CVE-2025-26010 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.
CVE-2025-26009 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 7.5 HIGH
Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.
CVE-2025-26008 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.
CVE-2025-26007 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.
CVE-2025-26006 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.
CVE-2025-26005 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.
CVE-2025-26004 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.
CVE-2025-26003 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.
CVE-2025-26002 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 9.8 CRITICAL
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.
CVE-2025-26001 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2026-06-17 N/A 7.5 HIGH
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
CVE-2025-25997 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 7.5 HIGH
Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.
CVE-2025-25994 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.
CVE-2025-25993 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 5.1 MEDIUM
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."
CVE-2025-25992 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 5.1 MEDIUM
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.
CVE-2025-25991 1 Hoosk 1 Hoosk 2026-06-17 N/A 5.1 MEDIUM
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.