0.0

CVE-2025-67147 -

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (…

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 9:05 p.m.

0.0

CVE-2025-67146 -

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issu…

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 9:10 p.m.

0.0

CVE-2021-41074 -

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 8:24 p.m.

0.0

CVE-2025-46068 -

An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:30 p.m.

0.0

CVE-2025-29329 -

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 9:44 p.m.

0.0

CVE-2025-51567 -

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 7:22 p.m.

0.0

CVE-2025-66689 -

A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system di…

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:42 p.m.

0.0

CVE-2025-46066 -

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:12 p.m.

0.0

CVE-2025-66802 -

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

πŸ“… Published: Jan. 12, 2026, midnight πŸ”„ Last Modified: Jan. 12, 2026, 7:10 p.m.

6.9

CVSS4.0

CVE-2026-0851 - code-projects Online Music Site AdminAddUser.php sql injection

A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publ…

πŸ“… Published: Jan. 11, 2026, 11:32 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 4:37 p.m.
Total resulsts: 327160
Page 15 of 32,716
Β« previous page Β» next page
Filters