Vulnerabilities (CVE)

Total 397901 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25516 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
CVE-2025-25515 1 Seacms 1 Seacms 2026-06-17 N/A 8.8 HIGH
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
CVE-2025-25514 1 Seacms 1 Seacms 2026-06-17 N/A 6.5 MEDIUM
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
CVE-2025-25513 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
CVE-2025-25510 1 Tenda 2 Ac8, Ac8 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.
CVE-2025-25507 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 6.5 MEDIUM
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
CVE-2025-25505 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
CVE-2025-25500 1 Cosmwasm 1 Cosmwasm 2026-06-17 N/A 7.5 HIGH
An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the blockchain.
CVE-2025-25497 2026-06-17 N/A 8.1 HIGH
An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.
CVE-2025-25478 1 Syspass 1 Syspass 2026-06-17 N/A 6.5 MEDIUM
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
CVE-2025-25477 1 Syspass 1 Syspass 2026-06-17 N/A 8.1 HIGH
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.
CVE-2025-25476 1 Syspass 1 Syspass 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.
CVE-2025-25475 2 Debian, Offis 2 Debian Linux, Dcmtk 2026-06-17 N/A 7.5 HIGH
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
CVE-2025-25474 2 Debian, Offis 2 Debian Linux, Dcmtk 2026-06-17 N/A 6.5 MEDIUM
DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.
CVE-2025-25473 2026-06-17 N/A 5.3 MEDIUM
FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.
CVE-2025-25472 2 Debian, Offis 2 Debian Linux, Dcmtk 2026-06-17 N/A 5.3 MEDIUM
A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.
CVE-2025-25471 2026-06-17 N/A 4.3 MEDIUM
FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.
CVE-2025-25469 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.5 MEDIUM
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.
CVE-2025-25468 1 Ffmpeg 1 Ffmpeg 2026-06-17 N/A 6.5 MEDIUM
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
CVE-2025-25467 2026-06-17 N/A 9.8 CRITICAL
Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.