6.9

CVSS4.0

CVE-2025-15243 - code-projects Simple Stock System login.php sql injection

A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Dec. 30, 2025, 10:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

2.3

CVSS4.0

CVE-2025-15242 - PHPEMS Coupon race condition

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as di…

πŸ“… Published: Dec. 30, 2025, 9:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

9.1

CVSS3.1

CVE-2025-15359 - DVP-12SE11T - Out-of-bound memory write Vulnerability

DVP-12SE11T - Out-of-bound memory write Vulnerability

πŸ“… Published: Dec. 30, 2025, 9:07 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 4:54 p.m.

7.5

CVSS3.1

CVE-2025-15358 - DVP-12SE11T - Denial of Service Vulnerability

DVP-12SE11T - Denial of Service Vulnerability

πŸ“… Published: Dec. 30, 2025, 9:04 a.m. πŸ”„ Last Modified: Jan. 6, 2026, 9:04 p.m.

5.1

CVSS4.0

CVE-2025-15241 - CloudPanel Community Edition HTTP Header users redirect

A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack re…

πŸ“… Published: Dec. 30, 2025, 9:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-15103 - DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

πŸ“… Published: Dec. 30, 2025, 8:55 a.m. πŸ”„ Last Modified: Jan. 6, 2026, 9:04 p.m.

9.1

CVSS3.1

CVE-2025-15102 - DVP-12SE11T - Password Protection Bypass

DVP-12SE11T - Password Protection Bypass

πŸ“… Published: Dec. 30, 2025, 8:48 a.m. πŸ”„ Last Modified: Jan. 6, 2026, 9:06 p.m.

8.7

CVSS4.0

CVE-2025-15234 - Tenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow

A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the…

πŸ“… Published: Dec. 30, 2025, 8:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

8.7

CVSS4.0

CVE-2025-15233 - Tenda M3 setAdInfoDetail formSetAdInfoDetails heap-based overflow

A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemU…

πŸ“… Published: Dec. 30, 2025, 8:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

5.1

CVSS4.0

CVE-2025-15355 - NetVision Information|ISOinsight - Reflected Cross-site Scripting

ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

πŸ“… Published: Dec. 30, 2025, 7:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348736
Page 2306 of 34,874
Β« previous page Β» next page
Filters