5.3

CVSS4.0

CVE-2025-13263 - SourceCodester Online Magazine Management System categories.php sql injection

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The attack is possible to be carried out remotely. The exploit is publ…

📅 Published: Nov. 17, 2025, 4:32 a.m. 🔄 Last Modified: Nov. 19, 2025, 1:15 p.m.

6.9

CVSS4.0

CVE-2025-13262 - lsfusion platform UploadFileRequestHandler.java UploadFileRequestHandler path traversal

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of the argument sid can lead to pa…

📅 Published: Nov. 17, 2025, 4:02 a.m. 🔄 Last Modified: Dec. 1, 2025, 3:31 p.m.

9.3

CVSS4.0

CVE-2025-13284 - ThinPLUS|ThinPLUS - OS Command Injection

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

📅 Published: Nov. 17, 2025, 3:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-13261 - lsfusion platform DownloadFileRequestHandler.java DownloadFileRequestHandler path traversal

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploit…

📅 Published: Nov. 17, 2025, 3:32 a.m. 🔄 Last Modified: Dec. 1, 2025, 3:30 p.m.

7

CVSS4.0

CVE-2025-13283 - Chunghwa Telecom|TenderDocTransfer - Arbitrary File Copy and Paste

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could u…

📅 Published: Nov. 17, 2025, 3:30 a.m. 🔄 Last Modified: Dec. 19, 2025, 5:01 p.m.

7

CVSS4.0

CVE-2025-13282 - Chunghwa Telecom|TenderDocTransfer - Arbitrary File Delete

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these …

📅 Published: Nov. 17, 2025, 3:24 a.m. 🔄 Last Modified: Dec. 19, 2025, 5:02 p.m.

5.3

CVSS4.0

CVE-2025-13260 - Campcodes Supplier Management System edit_product.php sql injection

A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument cmbProductUnit leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to th…

📅 Published: Nov. 17, 2025, 3:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

9.4

CVSS4.0

CVE-2025-10460 - Unsanitized parameter input leading to SQL Injection vulnerability

A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows an unauthorised user to retrieve sensitive database contents via unsanitized parameter input. This vulnerability occurs due to improper input validati…

📅 Published: Nov. 17, 2025, 2:48 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-13259 - Campcodes Supplier Management System edit_unit.php sql injection

A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

📅 Published: Nov. 17, 2025, 2:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

8.7

CVSS4.0

CVE-2025-13258 - Tenda AC20 WifiExtraSet buffer overflow

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is an unknown function of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

📅 Published: Nov. 17, 2025, 2:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:30 a.m.
Total resulsts: 346541
Page 2732 of 34,655
« previous page » next page
Filters