Total
397457 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-23001 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. NOTE: the Supplier's position is that the end user is supposed to edit the NGINX configuration template to set server_name (with this setting, Host header injection cannot occur). | |||||
| CVE-2025-22997 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter. | |||||
| CVE-2025-22996 | 1 Linksys | 2 E5600, E5600 Firmware | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter. | |||||
| CVE-2025-22994 | 1 Zoneland | 1 O2oa | 2026-06-17 | N/A | 6.1 MEDIUM |
| O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings. | |||||
| CVE-2025-22992 | 1 Openenergymonitor | 1 Emoncms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions. | |||||
| CVE-2025-22984 | 1 Thecosy | 1 Icecms | 2026-06-17 | N/A | 7.5 HIGH |
| An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. | |||||
| CVE-2025-22983 | 1 Thecosy | 1 Icecms | 2026-06-17 | N/A | 7.5 HIGH |
| An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. | |||||
| CVE-2025-22980 | 1 Slims | 1 Senayan Library Management System Bulian | 2026-06-17 | N/A | 6.7 MEDIUM |
| A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php. | |||||
| CVE-2025-22978 | 1 Eladmin | 1 Eladmin | 2026-06-17 | N/A | 9.8 CRITICAL |
| eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module. | |||||
| CVE-2025-22976 | 2026-06-17 | N/A | 7.1 HIGH | ||
| SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module. | |||||
| CVE-2025-22974 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component. | |||||
| CVE-2025-22973 | 1 Qibosoft | 1 Qibocms X1 | 2026-06-17 | N/A | 7.5 HIGH |
| An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content. | |||||
| CVE-2025-22968 | 1 Dlink | 2 Dwr-m972v, Dwr-m972v Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions | |||||
| CVE-2025-22964 | 1 Ddsn | 1 Cm3 Acora Content Management System | 2026-06-17 | N/A | 8.1 HIGH |
| DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application. | |||||
| CVE-2025-22963 | 1 Sismics | 1 Teedy | 2026-06-17 | N/A | 7.5 HIGH |
| Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin. | |||||
| CVE-2025-22962 | 2026-06-17 | N/A | 7.2 HIGH | ||
| A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json endpoint, enabling arbitrary command execution on the underlying system. This vulnerability can lead to full system compromise, including unauthorized access, privilege escalation, and potentially full device takeover. | |||||
| CVE-2025-22961 | 2026-06-17 | N/A | 8.0 HIGH | ||
| A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access Control (CWE-284). Unauthenticated attackers can directly access sensitive database backup files (snapshot_users.db) via publicly exposed URLs (/logs/devcfg/snapshot/ and /logs/devcfg/user/). Exploiting this vulnerability allows retrieval of sensitive user data, including login credentials, potentially leading to full system compromise. | |||||
| CVE-2025-22960 | 2026-06-17 | N/A | 8.0 HIGH | ||
| A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files (/logs/debug/xteLog*), potentially revealing sensitive session-related information such as session IDs (sess_id) and authentication success tokens (user_check_password OK). Exploiting this flaw could allow attackers to hijack active sessions, gain unauthorized access, and escalate privileges on affected devices. | |||||
| CVE-2025-22957 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information. | |||||
| CVE-2025-22956 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains a secret only intended to be accessible by a subset of clients. One example of this is a domain join account password for the windomain package. | |||||
