Total
397453 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-22946 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution. | |||||
| CVE-2025-22941 | 1 Adtran | 2 411, 411 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands. | |||||
| CVE-2025-22940 | 1 Adtran | 2 411, 411 Firmware | 2026-06-17 | N/A | 9.1 CRITICAL |
| Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password. | |||||
| CVE-2025-22939 | 1 Adtran | 2 411, 411 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands. | |||||
| CVE-2025-22938 | 1 Adtran | 2 411, 411 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords. | |||||
| CVE-2025-22937 | 1 Adtran | 2 411, 411 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors. | |||||
| CVE-2025-22931 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 7.5 HIGH |
| An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members. | |||||
| CVE-2025-22930 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 9.8 CRITICAL |
| OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php. | |||||
| CVE-2025-22929 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 9.8 CRITICAL |
| OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php. | |||||
| CVE-2025-22928 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 9.8 CRITICAL |
| OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php. | |||||
| CVE-2025-22927 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 9.1 CRITICAL |
| An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. | |||||
| CVE-2025-22926 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. | |||||
| CVE-2025-22925 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 7.5 HIGH |
| OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability. | |||||
| CVE-2025-22924 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 8.8 HIGH |
| OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php. | |||||
| CVE-2025-22923 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 8.8 HIGH |
| An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile. | |||||
| CVE-2025-22921 | 2 Debian, Ffmpeg | 2 Debian Linux, Ffmpeg | 2026-06-17 | N/A | 6.5 MEDIUM |
| FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c. | |||||
| CVE-2025-22920 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS). | |||||
| CVE-2025-22919 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. | |||||
| CVE-2025-22918 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information. | |||||
| CVE-2025-22917 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious payload into the 'type' parameter of list.php. | |||||
