5.1

CVSS4.0

CVE-2025-10642 - wangchenyi1996 chat_forum q.php cross site scripting

A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts an unknown function of the file /q.php. Such manipulation of the argument path leads to cross site scripting. The attack may be launched remotely. This product operates on a roll…

πŸ“… Published: Sept. 18, 2025, 1:32 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 1:32 a.m.

5.3

CVSS4.0

CVE-2025-10634 - D-Link DIR-823X Environment Variable goahead sub_412E7C command injection

A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The at…

πŸ“… Published: Sept. 18, 2025, 1:02 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 1:02 a.m.

5.1

CVSS4.0

CVE-2025-10632 - itsourcecode Online Petshop Management System Admin Dashboard availableframe.php cross site scripti…

A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to lau…

πŸ“… Published: Sept. 18, 2025, 1:02 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 1:02 a.m.

5.1

CVSS4.0

CVE-2025-10631 - itsourcecode Online Petshop Management System Available Products addcnp.php cross site scripting

A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attac…

πŸ“… Published: Sept. 18, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 12:32 a.m.

5.3

CVSS4.0

CVE-2025-10629 - D-Link DIR-852 Simple Service Discovery Protocol Service cgibin ssdpcgi_main command injection

A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery Protocol Service. Executing manipulation of the argument ST can lead to command injection. The attack may be performed from r…

πŸ“… Published: Sept. 18, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 12:32 a.m.

5.3

CVSS4.0

CVE-2025-10628 - D-Link DIR-852 Web Management hedwig.cgi command injection

A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has b…

πŸ“… Published: Sept. 18, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 18, 2025, 12:02 a.m.

5.3

CVSS4.0

CVE-2025-10627 - SourceCodester Online Exam Form Submission delete_user.php sql injection

A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/delete_user.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may b…

πŸ“… Published: Sept. 17, 2025, 11:32 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 11:32 p.m.

5.3

CVSS4.0

CVE-2025-10626 - SourceCodester Online Exam Form Submission update_s3.php sql injection

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /admin/update_s3.php. This manipulation of the argument credits causes sql injection. Remote exploitation of the attack is possible. The exploit has been publish…

πŸ“… Published: Sept. 17, 2025, 11:32 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 11:32 p.m.

5.3

CVSS4.0

CVE-2025-10625 - SourceCodester Online Exam Form Submission dashboard.php sql injection

A vulnerability was detected in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /user/dashboard.php?page=update_profile. The manipulation of the argument phone results in sql injection. The attack may be launched remotely. The e…

πŸ“… Published: Sept. 17, 2025, 11:02 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 11:02 p.m.

6.9

CVSS4.0

CVE-2025-10624 - PHPGurukul User Management System login.php sql injection

A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument emailid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may …

πŸ“… Published: Sept. 17, 2025, 10:32 p.m. πŸ”„ Last Modified: Sept. 17, 2025, 10:32 p.m.
Total resulsts: 310453
Page 1 of 31,046
Β» next page
Filters