6.9

CVSS4.0

CVE-2025-10565 - Campcodes Grocery Sales and Inventory System ajax.php sql injection

A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_receiving. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote.…

πŸ“… Published: Sept. 16, 2025, 8:32 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:32 p.m.

6.9

CVSS4.0

CVE-2025-10564 - Campcodes Grocery Sales and Inventory System ajax.php sql injection

A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=delete_category. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been m…

πŸ“… Published: Sept. 16, 2025, 8:32 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:32 p.m.

6.9

CVSS4.0

CVE-2025-10563 - Campcodes Grocery Sales and Inventory System ajax.php sql injection

A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_category. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the pu…

πŸ“… Published: Sept. 16, 2025, 8:02 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 8:02 p.m.

9.3

CVSS4.0

CVE-2025-34187 - Ilevia EVE X1/X5 Server 4.7.18.0.eden Reverse Rootshell

Ilevia EVE X1/X5 Server version ≀ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Exec…

πŸ“… Published: Sept. 16, 2025, 7:45 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 7:45 p.m.

9.3

CVSS4.0

CVE-2025-34186 - Ilevia EVE X1/X5 Server 4.7.18.0.eden Authentication Bypass

Ilevia EVE X1/X5 Server version ≀ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero…

πŸ“… Published: Sept. 16, 2025, 7:45 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 7:45 p.m.

8.7

CVSS4.0

CVE-2025-34185 - Ilevia EVE X1 Server 4.7.18.0.eden Unauthenticated File Disclosure

Ilevia EVE X1 Server version ≀ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.

πŸ“… Published: Sept. 16, 2025, 7:44 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 7:44 p.m.

9.3

CVSS4.0

CVE-2025-34184 - Ilevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection

Ilevia EVE X1 Server version ≀ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or den…

πŸ“… Published: Sept. 16, 2025, 7:40 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 7:40 p.m.

9.3

CVSS4.0

CVE-2025-34183 - Ilevia EVE X1 Server 4.7.18.0.eden Credentials Leak Through Log Disclosure

Ilevia EVE X1 Server version ≀ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential re…

πŸ“… Published: Sept. 16, 2025, 7:39 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 7:40 p.m.

6.9

CVSS4.0

CVE-2025-10562 - Campcodes Grocery Sales and Inventory System ajax.php sql injection

A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be …

πŸ“… Published: Sept. 16, 2025, 7:02 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 7:02 p.m.

4

CVSS3.1

CVE-2025-49728 - Microsoft PC Manager Security Feature Bypass Vulnerability

Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

πŸ“… Published: Sept. 16, 2025, 6:13 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 6:13 p.m.
Total resulsts: 310216
Page 1 of 31,022
Β» next page
Filters