Total
397441 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-22219 | 1 Vmware | 2 Aria Operations For Logs, Cloud Foundation | 2026-06-17 | N/A | 6.8 MEDIUM |
| VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user. | |||||
| CVE-2025-22218 | 1 Vmware | 2 Aria Operations For Logs, Cloud Foundation | 2026-06-17 | N/A | 8.5 HIGH |
| VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs | |||||
| CVE-2025-22217 | 2026-06-17 | N/A | 8.6 HIGH | ||
| Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access. | |||||
| CVE-2025-22216 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones. | |||||
| CVE-2025-22215 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network. | |||||
| CVE-2025-22214 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection. | |||||
| CVE-2025-22213 | 2026-06-17 | N/A | N/A | ||
| Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions. | |||||
| CVE-2025-22212 | 1 Convert Forms Project | 1 Convert Forms | 2026-06-17 | N/A | 2.7 LOW |
| A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend. | |||||
| CVE-2025-22211 | 1 Webdesigner-profi | 1 Joomshopping | 2026-06-17 | N/A | 3.4 LOW |
| A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend. | |||||
| CVE-2025-22210 | 1 Hikashop | 1 Hikashop | 2026-06-17 | N/A | 7.2 HIGH |
| A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend. | |||||
| CVE-2025-22209 | 1 Joomsky | 1 Js Jobs | 2026-06-17 | N/A | 4.7 MEDIUM |
| A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature. | |||||
| CVE-2025-22208 | 1 Joomsky | 1 Js Jobs | 2026-06-17 | N/A | 4.7 MEDIUM |
| A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature. | |||||
| CVE-2025-22207 | 2026-06-17 | N/A | N/A | ||
| Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. | |||||
| CVE-2025-22206 | 1 Joomsky | 1 Js Jobs | 2026-06-17 | N/A | 4.7 MEDIUM |
| A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'fieldfor' parameter in the GDPR Field feature. | |||||
| CVE-2025-22204 | 1 Regularlabs | 1 Sourcerer | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. | |||||
| CVE-2025-22178 | 1 Atlassian | 1 Jira Align | 2026-06-17 | N/A | 4.3 MEDIUM |
| Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page. | |||||
| CVE-2025-22177 | 1 Atlassian | 1 Jira Align | 2026-06-17 | N/A | 4.3 MEDIUM |
| Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews. | |||||
| CVE-2025-22176 | 1 Atlassian | 1 Jira Align | 2026-06-17 | N/A | 4.3 MEDIUM |
| Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items. | |||||
| CVE-2025-22175 | 1 Atlassian | 1 Jira Align | 2026-06-17 | N/A | 5.4 MEDIUM |
| Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist. | |||||
| CVE-2025-22174 | 1 Atlassian | 1 Jira Align | 2026-06-17 | N/A | 4.3 MEDIUM |
| Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission. | |||||
