6.9

CVSS4.0

CVE-2025-15167 - itsourcecode Online Cake Ordering System detailtransac.php sql injection

A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may …

πŸ“… Published: Dec. 29, 2025, 2:02 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.

6.9

CVSS4.0

CVE-2025-15166 - itsourcecode Online Cake Ordering System updatesupplier.php sql injection

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be u…

πŸ“… Published: Dec. 29, 2025, 1:32 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.

6.9

CVSS4.0

CVE-2025-15165 - itsourcecode Online Cake Ordering System updatecustomer.php sql injection

A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustomer.php?action=edit. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed t…

πŸ“… Published: Dec. 29, 2025, 1:02 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.

8.5

CVSS4.0

CVE-2025-15067 - Unrestricted File Upload and RCE in Innorix WP

Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

πŸ“… Published: Dec. 29, 2025, 12:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15066 - Arbitrary File Download through Path Traversal in Innorix WP

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

πŸ“… Published: Dec. 29, 2025, 12:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-15164 - Tenda WH450 SafeMacFilter stack-based overflow

A security flaw has been discovered in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be …

πŸ“… Published: Dec. 29, 2025, 12:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

8.6

CVSS4.0

CVE-2025-15065 - Data Exposure in Kings Information & Network KESS Enterprise

Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privilege Escalation, Modify Existing Service, Modify Shared File.…

πŸ“… Published: Dec. 29, 2025, 12:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-15163 - Tenda WH450 SafeEmailFilter stack-based overflow

A vulnerability was identified in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly av…

πŸ“… Published: Dec. 29, 2025, 12:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:09 a.m.

9.8

CVSS3.1

CVE-2025-56333 -

An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:14 p.m.

9.8

CVSS3.1

CVE-2025-68706 -

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attack…

πŸ“… Published: Dec. 29, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 2:21 a.m.
Total resulsts: 346582
Page 2130 of 34,659
Β« previous page Β» next page
Filters