6.9

CVSS4.0

CVE-2025-13241 - code-projects Student Information System index.php sql injection

A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

πŸ“… Published: Nov. 16, 2025, 7:02 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 7:02 a.m.

6.9

CVSS4.0

CVE-2025-13240 - code-projects Student Information System searchquery.php sql injection

A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

πŸ“… Published: Nov. 16, 2025, 6:32 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 6:32 a.m.

5.3

CVSS4.0

CVE-2025-13239 - Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution submit_checkout behavioral wo…

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument order_total_amount/cart_total_amount leads to enforcement of be…

πŸ“… Published: Nov. 16, 2025, 6:02 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 6:02 a.m.

5.3

CVSS4.0

CVE-2025-13238 - Bdtask Flight Booking Software Edit Profile edit unrestricted upload

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely. The exploit has been…

πŸ“… Published: Nov. 16, 2025, 5:32 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 5:32 a.m.

6.9

CVSS4.0

CVE-2025-13237 - itsourcecode Inventory Management System LogSignModal.PHP sql injection

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public …

πŸ“… Published: Nov. 16, 2025, 5:02 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 5:02 a.m.

7.5

CVSS3.1

CVE-2025-12482 - Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via…

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the β€˜search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu…

πŸ“… Published: Nov. 16, 2025, 4:17 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 4:17 a.m.

5.3

CVSS4.0

CVE-2025-13236 - itsourcecode Inventory Management System index.php sql injection

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and m…

πŸ“… Published: Nov. 16, 2025, 4:02 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 4:02 a.m.

6.9

CVSS4.0

CVE-2025-13235 - itsourcecode Inventory Management System login.php sql injection

A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly dis…

πŸ“… Published: Nov. 16, 2025, 3:32 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 3:32 a.m.

5.3

CVSS4.0

CVE-2025-13234 - itsourcecode Inventory Management System index.php sql injection

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made …

πŸ“… Published: Nov. 16, 2025, 3:02 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 3:02 a.m.

6.9

CVSS4.0

CVE-2025-13233 - itsourcecode Inventory Management System index.php sql injection

A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to t…

πŸ“… Published: Nov. 16, 2025, 2:32 a.m. πŸ”„ Last Modified: Nov. 16, 2025, 2:32 a.m.
Total resulsts: 318415
Page 2 of 31,842
Β« previous page Β» next page
Filters