Vulnerabilities (CVE)

Total 397901 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25776 1 Codeastro 1 Bus Ticket Booking System 2026-06-17 N/A 5.0 MEDIUM
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
CVE-2025-25775 1 Codeastro 1 Bus Ticket Booking System 2026-06-17 N/A 9.8 CRITICAL
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
CVE-2025-25774 1 Open5gs 1 Open5gs 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).
CVE-2025-25772 1 Ujcms 1 Jspxcms 2026-06-17 N/A 5.1 MEDIUM
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
CVE-2025-25770 1 Wang.market 1 Wangmarket 2026-06-17 N/A 6.8 MEDIUM
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.
CVE-2025-25769 1 Wang.market 1 Wangmarket 2026-06-17 N/A 8.0 HIGH
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.
CVE-2025-25768 1 Mrcms 1 Mrcms 2026-06-17 N/A 5.4 MEDIUM
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2025-25767 1 Mrcms 1 Mrcms 2026-06-17 N/A 4.8 MEDIUM
A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.
CVE-2025-25766 1 Mrcms 1 Mrcms 2026-06-17 N/A 4.8 MEDIUM
An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
CVE-2025-25765 1 Mrcms 1 Mrcms 2026-06-17 N/A 4.0 MEDIUM
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.
CVE-2025-25763 1 Crmeb 1 Crmeb 2026-06-17 N/A 9.8 CRITICAL
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVE-2025-25761 1 Hkcms 1 Hkcms 2026-06-17 N/A 7.2 HIGH
HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.
CVE-2025-25760 1 Sucms Project 1 Sucms 2026-06-17 N/A 7.5 HIGH
A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request.
CVE-2025-25759 1 Sucms Project 1 Sucms 2026-06-17 N/A 7.5 HIGH
An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.
CVE-2025-25758 1 Kukufm 1 Kukufm 2026-06-17 N/A 7.5 HIGH
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
CVE-2025-25749 1 Digitaldruid 1 Hoteldruid 2026-06-17 N/A 7.1 HIGH
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
CVE-2025-25748 1 Digitaldruid 1 Hoteldruid 2026-06-17 N/A 7.3 HIGH
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.
CVE-2025-25747 1 Digitaldruid 1 Hoteldruid 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
CVE-2025-25746 1 Dlink 2 Dir-853, Dir-853 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.
CVE-2025-25745 1 Dlink 2 Dir-853, Dir-853 Firmware 2026-06-17 N/A 8.8 HIGH
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetQuickVPNSettings module.