Search

Found 17,412 results in 772ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-9419 critical 9.8 9.8 admerc 10mo ago A vulnerability was detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /unit/addunit.php. Performing manipulation of the argument ID res…
CVE-2025-9418 critical 9.8 9.8 admerc 10mo ago A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /owner/addowner.php. Such manipulation of the argument ID leads…
CVE-2025-9416 low 2.4 2.4 10mo ago A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file /cms/webpage/ of the component Pages Image Handler. The manipulation results i…
CVE-2025-9415 critical 9.8 9.8 njtech 10mo ago A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads to unrest…
CVE-2025-9413 critical 9.8 9.8 lostvip 10mo ago A flaw has been found in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/system/system_router.go. This manipulation of the argument orderByColumn/isAsc …
CVE-2025-9412 critical 9.8 9.8 lostvip 10mo ago A vulnerability was detected in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file modules/system/dao/DictDataDao.go. The manipulation of the argument orderByColum…
CVE-2025-9411 critical 9.8 9.8 lostvip 10mo ago A security vulnerability has been detected in lostvip-com ruoyi-go up to 2.1. The impacted element is the function SelectPageList of the file modules/system/service/LoginInforService.go. The manipula…
CVE-2025-9410 critical 9.8 9.8 lostvip 10mo ago A weakness has been identified in lostvip-com ruoyi-go up to 2.1. The affected element is the function SelectListByPage of the file modules/system/dao/GenTableDao.go. Executing manipulation of the ar…
CVE-2025-9406 critical 9.8 9.8 mossle 10mo ago A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.u…
CVE-2025-9401 low 3.7 3.7 utcms_project 10mo ago A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulation of the argument …
CVE-2025-9397 critical 9.8 9.8 vvveb 10mo ago A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipulation of the argument files[] can lead to unrestri…
CVE-2025-9391 critical 9.8 9.8 zhiyou-group 10mo ago A weakness has been identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this issue is the function getFieldValue of the component com.artery.workflow.ServiceImpl. This manipulation of the argumen…
CVE-2025-9387 critical 9.8 9.8 10mo ago A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Perf…
CVE-2025-9383 low 2.5 2.5 10mo ago A security vulnerability has been detected in FNKvision Y215 CCTV Camera 10.194.120.40. This issue affects the function crypt of the file /etc/passwd. The manipulation leads to use of weak hash. The …
CVE-2025-9381 low 1.6 1.6 10mo ago A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an unknown part of the file /tmp/wpa_supplicant.conf. Performing manipulation results in information disc…
CVE-2025-9311 critical 9.8 9.8 admerc 10mo ago A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fair/addfair.php. The manipulation of the argument ID…
CVE-2025-9307 critical 9.8 9.8 phpgurukul 10mo ago A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. T…
CVE-2025-9305 critical 9.8 9.8 oretnom23 10mo ago A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the file /bank/mnotice.php. The manipulation of the argu…
CVE-2025-9304 critical 9.8 9.8 oretnom23 10mo ago A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of the file /bank/show.php. Executing manipulation of the argument ID can lead to s…
CVE-2025-9302 critical 9.8 9.8 phpgurukul 10mo ago A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql inject…
CVE-2025-9301 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable ass…
CVE-2025-9296 critical 9.8 9.8 emlog 10mo ago A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image lea…
CVE-2025-49410 critical 10.0 10.0 10mo ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Testimonials: from n/a through…
CVE-2025-49409 critical 9.8 9.8 10mo ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPress allows Stored XSS. This issue affects SensorPress: from n/a through 1.0.
CVE-2025-49408 critical 10.0 10.0 10mo ago Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This issue affects Templately: from n/a through 3.2.7.
CVE-2025-49400 critical 9.8 9.8 10mo ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visi…
CVE-2025-9193 low 3.5 3.5 10mo ago A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to ope…
CVE-2025-9165 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipul…
CVE-2025-9156 critical 9.8 9.8 angeljudesuarez 10mo ago A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results…
CVE-2025-9155 critical 9.8 9.8 mayurik 10mo ago A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation of the argument e…
CVE-2025-9154 critical 9.8 9.8 mayurik 10mo ago A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation of the argument emai…
CVE-2025-9149 critical 9.8 9.8 10mo ago A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command…
CVE-2025-9119 low 2.4 2.4 10mo ago A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSI…
CVE-2025-9109 low 3.7 3.7 portabilis 10mo ago A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpo…
CVE-2025-9103 low 2.4 2.4 10mo ago A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be …
CVE-2025-9096 low 3.5 3.5 10mo ago ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
CVE-2025-9095 low 3.5 3.5 10mo ago ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/users.js
CVE-2025-9090 critical 9.8 10.0 EXP 10mo ago A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injecti…
CVE-2025-9053 critical 9.8 9.8 projectworlds 10mo ago A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /updatesubcategory.php. The manipulation of the argument t1/s1 leads …
CVE-2025-9052 critical 9.8 9.8 projectworlds 10mo ago A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /updatepackage.php. The manipulation of the argument s1 leads to sql injection. …
CVE-2025-9051 critical 9.8 9.8 projectworlds 10mo ago A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /updatecategory.php. The manipulation of the argument t1…
CVE-2025-9050 critical 9.8 9.8 projectworlds 10mo ago A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /addcategory.php. The manipulation of the argument t1 l…
CVE-2025-9047 critical 9.8 9.8 projectworlds 10mo ago A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /visitor_out.php. The manipulation of the argument rid leads to sql injectio…
CVE-2025-9028 critical 9.8 9.8 anisha 10mo ago A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /adphar.php. Executing manipulation of the argument phuname can lead to sql injec…
CVE-2025-9027 critical 9.8 9.8 anisha 10mo ago A vulnerability has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /addelivery.php. The manipulation of the argument deName leads to sql in…
CVE-2025-9026 critical 9.8 9.8 10mo ago A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads…
CVE-2025-9024 critical 9.8 9.8 phpgurukul 10mo ago A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appointment.php. The manipulation of the arg…
CVE-2025-9022 critical 9.8 9.8 oretnom23 10mo ago A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statements.php. The manipulation of the argument…
CVE-2025-9021 critical 9.8 9.8 oretnom23 10mo ago A vulnerability was determined in SourceCodester Online Bank Management System up to 1.0. This vulnerability affects unknown code of the file /bank/transfer.php. The manipulation of the argument emai…
CVE-2025-9013 critical 9.8 9.8 phpgurukul 10mo ago A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument …
CVE-2025-9012 critical 9.8 9.8 phpgurukul 10mo ago A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpin…
CVE-2025-9011 critical 9.8 9.8 phpgurukul 10mo ago A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argumen…
CVE-2025-9010 critical 9.8 9.8 mayurik 10mo ago A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking_report.php. The manipulat…
CVE-2025-9009 critical 9.8 9.8 mayurik 10mo ago A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/email_setup.php. The manipulation of the argument Name …
CVE-2025-9008 critical 9.8 9.8 mayurik 10mo ago A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the arg…
CVE-2025-9005 low 3.7 3.7 mtons 10mo ago A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible …
CVE-2025-9004 critical 9.1 9.1 mtons 10mo ago A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentica…
CVE-2025-9002 critical 9.8 9.8 surbowl 10mo ago A vulnerability was identified in Surbowl dormitory-management-php 1.0. This affects an unknown part of the file login.php. The manipulation of the argument Account leads to sql injection. It is poss…
CVE-2025-8993 critical 9.8 9.8 mayurik 10mo ago A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/expense_report.php. The manipulation of the argument from_date …
CVE-2025-8990 critical 9.8 9.8 anisha 10mo ago A vulnerability was determined in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /browsemdcn.php. The manipulation of the argument Search leads to sql injection.…
CVE-2025-8989 critical 9.8 9.8 unyasoft 10mo ago A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. This issue affects some unknown processing of the file /edit-phlebotomist.php. The manipulation of the argument mob…
CVE-2025-8988 critical 9.8 9.8 unyasoft 10mo ago A vulnerability has been found in SourceCodester COVID 19 Testing Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation of the argume…
CVE-2025-8987 critical 9.8 9.8 unyasoft 10mo ago A vulnerability was identified in SourceCodester COVID 19 Testing Management System 1.0. This affects an unknown part of the file /test-details.php. The manipulation of the argument remark leads to s…
CVE-2025-8986 critical 9.8 9.8 unyasoft 10mo ago A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /search-report-result.php. The manipulation o…
CVE-2025-8985 critical 9.8 9.8 unyasoft 10mo ago A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argume…
CVE-2025-8984 critical 9.8 9.8 mayurik 10mo ago A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/expense_category.php. The manipulation of th…
CVE-2025-8983 critical 9.8 9.8 mayurik 10mo ago A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/expense.php. The manipulation of …
CVE-2025-8982 critical 9.8 9.8 mayurik 10mo ago A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/currency.php. The manipulation of th…
CVE-2025-8981 critical 9.8 9.8 mayurik 10mo ago A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/payment.php. The manipulation of the argument paymen…
CVE-2025-8974 critical 9.8 9.8 linlinjava 10mo ago A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHe…
CVE-2025-8973 critical 9.8 9.8 oretnom23 10mo ago A vulnerability has been found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the file /Actions.php. The manipulation of the argument Username leads to sql injection…
CVE-2025-8972 critical 9.8 9.8 mayurik 10mo ago A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argu…
CVE-2025-8971 critical 9.8 9.8 mayurik 10mo ago A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of …
CVE-2025-8970 critical 9.8 9.8 mayurik 10mo ago A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/booking.php. The manipulation of the argument ID lea…
CVE-2025-8969 critical 9.8 9.8 mayurik 10mo ago A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/approve_user.php. The manipulation…
CVE-2025-8968 critical 9.8 9.8 mayurik 10mo ago A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/disapprove_user.php. The man…
CVE-2025-8967 critical 9.8 9.8 mayurik 10mo ago A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/packages.php. The manipulation of the argume…
CVE-2025-8966 critical 9.8 9.8 mayurik 10mo ago A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/tax.php. The manipulation of the argum…
CVE-2025-8961 low 3.3 3.3 FIX slesdebian debian libtiff 10mo ago A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can …
CVE-2025-8960 critical 9.8 9.8 campcodes 10mo ago A vulnerability has been found in Campcodes Online Flight Booking Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/save_airlines.php. The manipulation of…
CVE-2025-8957 critical 9.8 9.8 campcodes 10mo ago A vulnerability was determined in Campcodes Online Flight Booking Management System 1.0. Affected is an unknown function of the file /flights.php. The manipulation of the argument departure_airport_i…
CVE-2025-28979 critical 9.8 9.8 thimpress 10mo ago Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PHP Local File Inclusion. This issue affects WP Pipe…
CVE-2025-8955 critical 9.8 9.8 code-projects 10mo ago A vulnerability has been found in PHPGurukul Hospital Management System 4.0. This vulnerability affects unknown code of the file /admin/edit-doctor.php. The manipulation of the argument docfees leads…
CVE-2025-8954 critical 9.8 9.8 code-projects 10mo ago A vulnerability was identified in PHPGurukul Hospital Management System 4.0. This affects an unknown part of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspeciliza…
CVE-2025-8953 critical 9.8 9.8 unyasoft 10mo ago A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /check_availability.php. The manipulation of …
CVE-2025-8952 critical 9.8 9.8 campcodes 10mo ago A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the componen…
CVE-2025-8951 critical 9.8 9.8 phpgurukul 10mo ago A vulnerability has been found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to…
CVE-2025-8950 critical 9.8 9.8 campcodes 10mo ago A vulnerability was identified in Campcodes Online Recruitment Management System 1.0. This issue affects some unknown processing of the file /Recruitment/index.php?page=view_vacancy. The manipulation…
CVE-2025-8948 critical 9.8 9.8 projectworlds 10mo ago A vulnerability was determined in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /front.php. The manipulation of the argument rid leads to sql injection. It …
CVE-2025-8947 critical 9.8 9.8 projectworlds 10mo ago A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of the file /query_data.php. The manipulation of the argument dateF/dateP leads to…
CVE-2025-8946 critical 9.8 9.8 projectworlds 10mo ago A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql i…
CVE-2025-8936 critical 9.8 9.8 1000projects 10mo ago A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the …
CVE-2025-8935 critical 9.8 9.8 1000projects 10mo ago A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argumen…
CVE-2025-8932 critical 9.8 9.8 1000projects 10mo ago A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalesca…
CVE-2012-10060 critical 9.8 10.0 EXP sysax 10mo ago Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies th…
CVE-2025-8927 low 3.7 3.7 mtons 10mo ago A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulati…
CVE-2025-8926 critical 9.8 9.8 unyasoft 10mo ago A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument…
CVE-2025-8925 critical 9.8 9.8 angeljudesuarez 10mo ago A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file /Admin/match.php. The manipulation of the argument code leads to sql injection…
CVE-2025-8924 critical 9.8 9.8 campcodes 10mo ago A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing of the file /viewbill.php. The manipulation of the argument ID leads to sql inj…
CVE-2025-8923 critical 9.8 9.8 anisha 10mo ago A vulnerability was determined in code-projects Job Diary 1.0. This vulnerability affects unknown code of the file /edit-details.php. The manipulation of the argument ID leads to sql injection. The a…