6.9
CVE-2025-15243 - code-projects Simple Stock System login.php sql injection
A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
2.3
CVE-2025-15242 - PHPEMS Coupon race condition
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as diβ¦
9.1
CVE-2025-15359 - DVP-12SE11T - Out-of-bound memory write Vulnerability
DVP-12SE11T - Out-of-bound memory write Vulnerability
7.5
CVE-2025-15358 - DVP-12SE11T - Denial of Service Vulnerability
DVP-12SE11T - Denial of Service Vulnerability
5.1
CVE-2025-15241 - CloudPanel Community Edition HTTP Header users redirect
A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack reβ¦
8.1
CVE-2025-15103 - DVP-12SE11T - Authentication Bypass via Partial Password Disclosure
DVP-12SE11T - Authentication Bypass via Partial Password Disclosure
9.1
CVE-2025-15102 - DVP-12SE11T - Password Protection Bypass
DVP-12SE11T - Password Protection Bypass
8.7
CVE-2025-15234 - Tenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate theβ¦
8.7
CVE-2025-15233 - Tenda M3 setAdInfoDetail formSetAdInfoDetails heap-based overflow
A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemUβ¦
5.1
CVE-2025-15355 - NetVision Informationο½ISOinsight - Reflected Cross-site Scripting
ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.