Vulnerabilities (CVE)

Total 397892 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25364 1 Connectify 1 Speedify 2026-06-17 N/A 8.4 HIGH
A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.
CVE-2025-25363 1 Thepluginpeople 1 Enterprise Mail Handler 2026-06-17 N/A 6.5 MEDIUM
An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload into the HTML field of a template.
CVE-2025-25362 2026-06-17 N/A 9.8 CRITICAL
A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.
CVE-2025-25361 1 Publiccms 1 Publiccms 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.
CVE-2025-25357 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the email POST request parameter.
CVE-2025-25356 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the " todate" POST request parameter.
CVE-2025-25355 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter.
CVE-2025-25354 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 7.2 HIGH
A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.
CVE-2025-25352 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.
CVE-2025-25351 1 Phpgurukul 1 Daily Expense Tracker System 2026-06-17 N/A 9.8 CRITICAL
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.
CVE-2025-25349 1 Phpgurukul 1 Daily Expense Tracker System 2026-06-17 N/A 9.8 CRITICAL
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.
CVE-2025-25343 1 Tenda 2 Ac6, Ac6 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
CVE-2025-25341 1 Libxmljs Project 1 Libxmljs 2026-06-17 N/A 7.5 HIGH
A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS).
CVE-2025-25334 2026-06-17 N/A 5.5 MEDIUM
An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-25333 2026-06-17 N/A 7.5 HIGH
An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-25331 2026-06-17 N/A 5.5 MEDIUM
An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-25330 2026-06-17 N/A 5.5 MEDIUM
An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-25329 2026-06-17 N/A 5.5 MEDIUM
An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-25326 2026-06-17 N/A 5.5 MEDIUM
An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-25325 2026-06-17 N/A 5.5 MEDIUM
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.