5.3

CVSS4.0

CVE-2025-15170 - Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting

A security vulnerability has been detected in Advaya Softech GEMS ERP Portal up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of the component Error Message Handler. The manipulation of the argument Message leads to cross site scripting. It is possible to initiate the atta…

πŸ“… Published: Dec. 29, 2025, 3:32 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 9:42 p.m.

5.1

CVSS4.0

CVE-2025-15169 - BiggiDroid Simple PHP CMS editsite.php sql injection

A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected by this issue is some unknown functionality of the file /admin/editsite.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available …

πŸ“… Published: Dec. 29, 2025, 3:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

6.9

CVSS4.0

CVE-2025-15168 - itsourcecode Student Management System statistical.php sql injection

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

πŸ“… Published: Dec. 29, 2025, 2:32 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:56 p.m.

10

CVSS3.1

CVE-2025-52691 - Upload Arbitrary Files

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

πŸ“… Published: Dec. 29, 2025, 2:15 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

6.9

CVSS4.0

CVE-2025-15167 - itsourcecode Online Cake Ordering System detailtransac.php sql injection

A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may …

πŸ“… Published: Dec. 29, 2025, 2:02 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.

6.9

CVSS4.0

CVE-2025-15166 - itsourcecode Online Cake Ordering System updatesupplier.php sql injection

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be u…

πŸ“… Published: Dec. 29, 2025, 1:32 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.

6.9

CVSS4.0

CVE-2025-15165 - itsourcecode Online Cake Ordering System updatecustomer.php sql injection

A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustomer.php?action=edit. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed t…

πŸ“… Published: Dec. 29, 2025, 1:02 a.m. πŸ”„ Last Modified: Dec. 30, 2025, 9:30 p.m.

8.5

CVSS4.0

CVE-2025-15067 - Unrestricted File Upload and RCE in Innorix WP

Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

πŸ“… Published: Dec. 29, 2025, 12:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15066 - Arbitrary File Download through Path Traversal in Innorix WP

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

πŸ“… Published: Dec. 29, 2025, 12:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-15164 - Tenda WH450 SafeMacFilter stack-based overflow

A security flaw has been discovered in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be …

πŸ“… Published: Dec. 29, 2025, 12:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.
Total resulsts: 349182
Page 2389 of 34,919
Β« previous page Β» next page
Filters