Vulnerabilities (CVE)

Total 397453 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-22946 1 Tenda 2 Ac9, Ac9 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.
CVE-2025-22941 1 Adtran 2 411, 411 Firmware 2026-06-17 N/A 9.8 CRITICAL
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.
CVE-2025-22940 1 Adtran 2 411, 411 Firmware 2026-06-17 N/A 9.1 CRITICAL
Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.
CVE-2025-22939 1 Adtran 2 411, 411 Firmware 2026-06-17 N/A 9.8 CRITICAL
A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.
CVE-2025-22938 1 Adtran 2 411, 411 Firmware 2026-06-17 N/A 9.8 CRITICAL
Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.
CVE-2025-22937 1 Adtran 2 411, 411 Firmware 2026-06-17 N/A 9.8 CRITICAL
An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.
CVE-2025-22931 1 Os4ed 1 Opensis 2026-06-17 N/A 7.5 HIGH
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members.
CVE-2025-22930 1 Os4ed 1 Opensis 2026-06-17 N/A 9.8 CRITICAL
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.
CVE-2025-22929 1 Os4ed 1 Opensis 2026-06-17 N/A 9.8 CRITICAL
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.
CVE-2025-22928 1 Os4ed 1 Opensis 2026-06-17 N/A 9.8 CRITICAL
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.
CVE-2025-22927 1 Os4ed 1 Opensis 2026-06-17 N/A 9.1 CRITICAL
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
CVE-2025-22926 1 Os4ed 1 Opensis 2026-06-17 N/A 9.8 CRITICAL
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
CVE-2025-22925 1 Os4ed 1 Opensis 2026-06-17 N/A 7.5 HIGH
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
CVE-2025-22924 1 Os4ed 1 Opensis 2026-06-17 N/A 8.8 HIGH
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
CVE-2025-22923 1 Os4ed 1 Opensis 2026-06-17 N/A 8.8 HIGH
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
CVE-2025-22921 2 Debian, Ffmpeg 2 Debian Linux, Ffmpeg 2026-06-17 N/A 6.5 MEDIUM
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.
CVE-2025-22920 2026-06-17 N/A 5.3 MEDIUM
A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).
CVE-2025-22919 2026-06-17 N/A 6.5 MEDIUM
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.
CVE-2025-22918 2026-06-17 N/A 7.5 HIGH
Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.
CVE-2025-22917 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious payload into the 'type' parameter of list.php.