Vulnerabilities (CVE)

Total 397901 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25462 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 5.5 MEDIUM
A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.
CVE-2025-25461 1 Seeddms 1 Seeddms 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS payload into the category name field. When a document is subsequently associated with this category, the payload is stored on the server and rendered without proper sanitization or output encoding. This results in the XSS payload executing in the browser of any user who views the document.
CVE-2025-25460 1 Flatpress 1 Flatpress 2026-06-17 N/A 4.8 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
CVE-2025-25458 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 4.6 MEDIUM
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
CVE-2025-25457 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
CVE-2025-25456 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
CVE-2025-25455 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
CVE-2025-25454 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
CVE-2025-25453 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 4.6 MEDIUM
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
CVE-2025-25452 1 Mytaag 1 Mytaag 2026-06-17 N/A 5.1 MEDIUM
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the "/user" endpoint
CVE-2025-25451 1 Mytaag 1 Mytaag 2026-06-17 N/A 5.1 MEDIUM
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the "2fa_authorized" Local Storage key
CVE-2025-25450 1 Mytaag 1 Mytaag 2026-06-17 N/A 5.1 MEDIUM
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated second factor to the /session endpoint
CVE-2025-25431 1 Trendnet 2 Tew-929dru, Tew-929dru Firmware 2026-06-17 N/A 4.8 MEDIUM
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.
CVE-2025-25430 1 Trendnet 2 Tew-929dru, Tew-929dru Firmware 2026-06-17 N/A 4.8 MEDIUM
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.
CVE-2025-25429 1 Trendnet 2 Tew-929dru, Tew-929dru Firmware 2026-06-17 N/A 4.8 MEDIUM
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.
CVE-2025-25428 1 Trendnet 2 Tew-929dru, Tew-929dru Firmware 2026-06-17 N/A 8.0 HIGH
TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
CVE-2025-25427 1 Tp-link 2 Wr841n, Wr841n Firmware 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of the JavaScript payload when the upnp page is loaded.
CVE-2025-25426 1 Guchengwuyue 1 Yshopmall 2026-06-17 N/A 7.2 HIGH
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
CVE-2025-25403 2026-06-17 N/A 9.8 CRITICAL
Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.
CVE-2025-25389 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.