6.9

CVSS4.0

CVE-2025-9419 - itsourcecode Apartment Management System addunit.php sql injection

A vulnerability was detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /unit/addunit.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be us…

πŸ“… Published: Aug. 25, 2025, 9:02 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 9:02 p.m.

6.9

CVSS4.0

CVE-2025-9418 - itsourcecode Apartment Management System addowner.php sql injection

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /owner/addowner.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publ…

πŸ“… Published: Aug. 25, 2025, 8:32 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 8:32 p.m.

7.5

CVSS3.1

CVE-2025-6188 - On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may …

On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of authentication.

πŸ“… Published: Aug. 25, 2025, 8:14 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 8:14 p.m.

3.8

CVSS3.1

CVE-2025-3456 - On affected platforms running Arista EOS, the global common encryption key configuration may be log…

On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol…

πŸ“… Published: Aug. 25, 2025, 8:02 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 8:31 p.m.

5.3

CVSS4.0

CVE-2025-9417 - itsourcecode Apartment Management System addemployee.php sql injection

A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /employee/addemployee.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made avai…

πŸ“… Published: Aug. 25, 2025, 8:02 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 8:30 p.m.

4.8

CVSS4.0

CVE-2025-9416 - oitcode samarium Pages Image webpage cross site scripting

A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file /cms/webpage/ of the component Pages Image Handler. The manipulation results in cross site scripting. The attack may be performed from a remote location. The exploit has been rel…

πŸ“… Published: Aug. 25, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 7:52 p.m.

5.3

CVSS4.0

CVE-2025-9415 - GreenCMS index.php unrestricted upload

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available …

πŸ“… Published: Aug. 25, 2025, 7:02 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 7:49 p.m.

5.1

CVSS4.0

CVE-2025-9414 - kalcaddle kodbox Download from Link serverDownload server-side request forgery

A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from Link Handler. Performing manipulation of the argument url results in server-side request forgery. Remote exploit…

πŸ“… Published: Aug. 25, 2025, 6:32 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 7 p.m.

5.3

CVSS4.0

CVE-2025-9413 - lostvip-com ruoyi-go system_router.go SelectListByPage sql injection

A flaw has been found in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/system/system_router.go. This manipulation of the argument orderByColumn/isAsc causes sql injection. The attack may be initiated remotely. The exploit has been published and may b…

πŸ“… Published: Aug. 25, 2025, 6:02 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 6:09 p.m.

6.1

CVSS4.0

CVE-2025-57811 - Craft Potential Remote Code Execution via Twig SSTI

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in vers…

πŸ“… Published: Aug. 25, 2025, 5:52 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 6:05 p.m.
Total resulsts: 307090
Page 21 of 30,709
Β« previous page Β» next page
Filters