Total
397901 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-25776 | 1 Codeastro | 1 Bus Ticket Booking System | 2026-06-17 | N/A | 5.0 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing. | |||||
| CVE-2025-25775 | 1 Codeastro | 1 Bus Ticket Booking System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder. | |||||
| CVE-2025-25774 | 1 Open5gs | 1 Open5gs | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS). | |||||
| CVE-2025-25772 | 1 Ujcms | 1 Jspxcms | 2026-06-17 | N/A | 5.1 MEDIUM |
| A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request. | |||||
| CVE-2025-25770 | 1 Wang.market | 1 Wangmarket | 2026-06-17 | N/A | 6.8 MEDIUM |
| Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java. | |||||
| CVE-2025-25769 | 1 Wang.market | 1 Wangmarket | 2026-06-17 | N/A | 8.0 HIGH |
| Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java. | |||||
| CVE-2025-25768 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload. | |||||
| CVE-2025-25767 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request. | |||||
| CVE-2025-25766 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 4.8 MEDIUM |
| An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file. | |||||
| CVE-2025-25765 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 4.0 MEDIUM |
| MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do. | |||||
| CVE-2025-25763 | 1 Crmeb | 1 Crmeb | 2026-06-17 | N/A | 9.8 CRITICAL |
| crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php | |||||
| CVE-2025-25761 | 1 Hkcms | 1 Hkcms | 2026-06-17 | N/A | 7.2 HIGH |
| HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php. | |||||
| CVE-2025-25760 | 1 Sucms Project | 1 Sucms | 2026-06-17 | N/A | 7.5 HIGH |
| A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request. | |||||
| CVE-2025-25759 | 1 Sucms Project | 1 Sucms | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request. | |||||
| CVE-2025-25758 | 1 Kukufm | 1 Kukufm | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml | |||||
| CVE-2025-25749 | 1 Digitaldruid | 1 Hoteldruid | 2026-06-17 | N/A | 7.1 HIGH |
| An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies. | |||||
| CVE-2025-25748 | 1 Digitaldruid | 1 Hoteldruid | 2026-06-17 | N/A | 7.3 HIGH |
| A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token. | |||||
| CVE-2025-25747 | 1 Digitaldruid | 1 Hoteldruid | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint | |||||
| CVE-2025-25746 | 1 Dlink | 2 Dir-853, Dir-853 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module. | |||||
| CVE-2025-25745 | 1 Dlink | 2 Dir-853, Dir-853 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetQuickVPNSettings module. | |||||
