Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-60302 |
|
Cross-Site Scripting (XSS) in fabian (CVE-2025-60302)
cross-site scripting in fabian (CVE-2025-60302). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-60828 |
|
Unsafe Deserialization in deserialization (CVE-2025-60828)
vulnerability in deserialization (CVE-2025-60828). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-0603 |
|
SQL Injection in sqli (CVE-2025-0603)
SQL injection in sqli (CVE-2025-0603). Successful exploitation can lead to full system takeover.
|
| CVE-2025-60967 |
|
Cross-Site Scripting (XSS) in endruntechnologies (CVE-2025-60967)
cross-site scripting in endruntechnologies (CVE-2025-60967). Confidential information can be exposed externally.
|
| CVE-2025-60969 |
|
Path Traversal in path-traversal (CVE-2025-60969)
path traversal in path-traversal (CVE-2025-60969). Confidential information can be exposed externally.
|
| CVE-2025-60963 |
|
OS Command Injection in dos (CVE-2025-60963)
OS command injection in dos (CVE-2025-60963). Data can be tampered with by attackers.
|
| CVE-2025-60964 |
|
OS Command Injection in dos (CVE-2025-60964)
OS command injection in dos (CVE-2025-60964). Successful exploitation can lead to full system takeover.
|
| CVE-2025-60965 |
|
OS Command Injection in dos (CVE-2025-60965)
OS command injection in dos (CVE-2025-60965). Successful exploitation can lead to full system takeover.
|
| CVE-2025-60957 |
|
OS Command Injection in dos (CVE-2025-60957)
OS command injection in dos (CVE-2025-60957). Successful exploitation can lead to full system takeover.
|
| CVE-2025-60960 |
|
OS Command Injection in dos (CVE-2025-60960)
OS command injection in dos (CVE-2025-60960). Data can be tampered with by attackers.
|
| CVE-2025-60958 |
|
Cross-Site Scripting (XSS) in endruntechnologies (CVE-2025-60958)
cross-site scripting in endruntechnologies (CVE-2025-60958). Confidential information can be exposed externally.
|
| CVE-2025-60961 |
|
Cross-Site Scripting (XSS) in endruntechnologies (CVE-2025-60961)
cross-site scripting in endruntechnologies (CVE-2025-60961). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-60956 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-60956)
vulnerability in csrf (CVE-2025-60956). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0609 |
|
Cross-Site Scripting (XSS) in c (CVE-2025-0609)
cross-site scripting in c (CVE-2025-0609). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-42193 |
|
Cross-Site Scripting (XSS) in nopcommerce (CVE-2021-42193)
cross-site scripting in nopcommerce (CVE-2021-42193). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10728 |
|
Vulnerability in dos (CVE-2025-10728)
vulnerability in dos (CVE-2025-10728). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-11234 |
|
Use-After-Free in dos (CVE-2025-11234)
vulnerability in dos (CVE-2025-11234). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-0876 |
|
Cross-Site Scripting (XSS) in CVE-2025-0876 (CVE-2025-0876)
cross-site scripting in CVE-2025-0876 (CVE-2025-0876). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-0616 |
|
SQL Injection in sqli (CVE-2025-0616)
SQL injection in sqli (CVE-2025-0616). Confidential information can be exposed externally.
|
| CVE-2025-22862 |
|
Vulnerability in fortinet (CVE-2025-22862)
vulnerability in fortinet (CVE-2025-22862). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0642 |
|
Vulnerability in CVE-2025-0642 (CVE-2025-0642)
vulnerability in CVE-2025-0642 (CVE-2025-0642). Confidential information can be exposed externally.
|
| CVE-2025-56588 |
|
Code Injection in dolibarr (CVE-2025-56588)
code injection in dolibarr (CVE-2025-56588). Successful exploitation can lead to full system takeover.
|
| CVE-2025-57393 |
|
Cross-Site Scripting (XSS) in CVE-2025-57393 (CVE-2025-57393)
cross-site scripting in CVE-2025-57393 (CVE-2025-57393). Successful exploitation can lead to full system takeover.
|
| CVE-2025-39901 |
|
Out-of-Bounds Read in linux (CVE-2025-39901)
vulnerability in linux (CVE-2025-39901). Confidential information can be exposed externally.
|
| CVE-2025-56513 |
|
Vulnerability in nicehash (CVE-2025-56513)
vulnerability in nicehash (CVE-2025-56513). Successful exploitation can lead to full system takeover.
|
| CVE-2025-56200 |
|
Cross-Site Scripting (XSS) in validator-project (CVE-2025-56200)
cross-site scripting in validator-project (CVE-2025-56200). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56571 |
|
Vulnerability in dos (CVE-2025-56571)
vulnerability in dos (CVE-2025-56571). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56572 |
|
Vulnerability in dos (CVE-2025-56572)
vulnerability in dos (CVE-2025-56572). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9230 |
|
Out-of-Bounds Read in dos (CVE-2025-9230)
vulnerability in dos (CVE-2025-9230). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9232 |
|
Out-of-Bounds Read in dos (CVE-2025-9232)
vulnerability in dos (CVE-2025-9232). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56807 |
|
Cross-Site Scripting (XSS) in fairsketch (CVE-2025-56807)
cross-site scripting in fairsketch (CVE-2025-56807). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-13150 |
|
SQL Injection in sqli (CVE-2024-13150)
SQL injection in sqli (CVE-2024-13150). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10035 KEV |
|
[KEV] Command Injection in Fortra goanywhere-mft (CVE-2025-10035)
command injection in Fortra goanywhere-mft (CVE-2025-10035). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-6396 |
|
Cross-Site Scripting (XSS) in CVE-2025-6396 (CVE-2025-6396)
cross-site scripting in CVE-2025-6396 (CVE-2025-6396). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10467 |
|
Cross-Site Scripting (XSS) in CVE-2025-10467 (CVE-2025-10467)
cross-site scripting in CVE-2025-10467 (CVE-2025-10467). Confidential information can be exposed externally.
|
| CVE-2025-10449 |
|
Path Traversal in path-traversal (CVE-2025-10449)
path traversal in path-traversal (CVE-2025-10449). Confidential information can be exposed externally.
|
| CVE-2020-36851 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-36851)
SSRF in ssrf (CVE-2020-36851). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10438 |
|
Vulnerability in path-traversal (CVE-2025-10438)
vulnerability in path-traversal (CVE-2025-10438). Confidential information can be exposed externally.
|
| CVE-2025-20362 KEV |
|
[KEV] Vulnerability in Cisco secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense (CVE-2025-20362)
vulnerability in Cisco secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense (CVE-2025-20362). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-9900 |
|
Vulnerability in dos (CVE-2025-9900)
vulnerability in dos (CVE-2025-9900). Successful exploitation can lead to full system takeover.
|
| CVE-2025-56304 |
|
Cross-Site Scripting (XSS) in yzmcms (CVE-2025-56304)
cross-site scripting in yzmcms (CVE-2025-56304). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2025-9798 |
|
Cross-Site Scripting (XSS) in CVE-2025-9798 (CVE-2025-9798)
cross-site scripting in CVE-2025-9798 (CVE-2025-9798). Confidential information can be exposed externally.
|
| CVE-2025-55887 |
|
Cross-Site Scripting (XSS) in ard (CVE-2025-55887)
cross-site scripting in ard (CVE-2025-55887). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-52367 |
|
Cross-Site Scripting (XSS) in pivotx (CVE-2025-52367)
cross-site scripting in pivotx (CVE-2025-52367). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55888 |
|
Cross-Site Scripting (XSS) in ard (CVE-2025-55888)
cross-site scripting in ard (CVE-2025-55888). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55885 |
|
SQL Injection in sqli (CVE-2025-55885)
SQL injection in sqli (CVE-2025-55885). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9035 |
|
Cross-Site Scripting (XSS) in CVE-2025-9035 (CVE-2025-9035)
cross-site scripting in CVE-2025-9035 (CVE-2025-9035). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8079 |
|
Cross-Site Scripting (XSS) in CVE-2025-8079 (CVE-2025-8079)
cross-site scripting in CVE-2025-8079 (CVE-2025-8079). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8664 |
|
Cross-Site Scripting (XSS) in CVE-2025-8664 (CVE-2025-8664)
cross-site scripting in CVE-2025-8664 (CVE-2025-8664). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10468 |
|
Path Traversal in path-traversal (CVE-2025-10468)
path traversal in path-traversal (CVE-2025-10468). Confidential information can be exposed externally.
|