Vulnerabilities (CVE)

Total 397901 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25621 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 4.3 MEDIUM
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.
CVE-2025-25620 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 5.4 MEDIUM
Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
CVE-2025-25618 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 3.3 LOW
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.
CVE-2025-25617 2026-06-17 N/A 4.3 MEDIUM
Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.
CVE-2025-25616 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 4.3 MEDIUM
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
CVE-2025-25615 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 2.7 LOW
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
CVE-2025-25614 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 8.8 HIGH
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.
CVE-2025-25610 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
CVE-2025-25609 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 8.0 HIGH
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
CVE-2025-25605 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.5 MEDIUM
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.
CVE-2025-25604 1 Totolink 2 X5000r, X5000r Firmware 2026-06-17 N/A 6.5 MEDIUM
Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
CVE-2025-25598 1 Inovalogic 1 Customer Monitor 2026-06-17 N/A 8.8 HIGH
Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.
CVE-2025-25595 1 Iitb 1 Safe 2026-06-17 N/A 9.8 CRITICAL
A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.
CVE-2025-25590 1 R1bbit 1 Yimioa 2026-06-17 N/A 6.1 MEDIUM
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.
CVE-2025-25589 2026-06-17 N/A 8.1 HIGH
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.
CVE-2025-25586 1 R1bbit 1 Yimioa 2026-06-17 N/A 4.2 MEDIUM
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.
CVE-2025-25585 1 R1bbit 1 Yimioa 2026-06-17 N/A 7.3 HIGH
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
CVE-2025-25582 1 R1bbit 1 Yimioa 2026-06-17 N/A 6.1 MEDIUM
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.
CVE-2025-25580 1 R1bbit 1 Yimioa 2026-06-17 N/A 6.1 MEDIUM
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.
CVE-2025-25579 1 Totolink 2 A3002r, A3002r Firmware 2026-06-17 N/A 9.8 CRITICAL
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.