9.3
CVE-2025-12866 - Hundred Plus๏ฝEIP Plus - Weak Password Recovery Mechanism
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
5.1
CVE-2025-12927 - DedeBIZ archives_add.php sql injection
A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of the argument flags[] leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may โฆ
8.7
CVE-2025-12865 - e-Excellence๏ฝU-Office Force - SQL Injection
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.
8.7
CVE-2025-12864 - e-Excellence๏ฝU-Office Force - SQL Injection
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.
5.3
CVE-2025-12926 - SourceCodester Farm Management System review.php sql injection
A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the pubโฆ
6.9
CVE-2025-12925 - rymcu forest UserDicController.java deleteDic authorization
A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing authorization. The attack โฆ
5.3
CVE-2025-12924 - rymcu forest BankController.java GlobalResult authorization
A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing authorization. The attack may be initiated remotโฆ
5.1
CVE-2025-12923 - liweiyi ChestnutCMS download resourceDownload path traversal
A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publiclโฆ
5.3
CVE-2025-12922 - OpenClinica Community Edition CRF Data Import ImportCRFData path traversal
A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data Import. Performing manipulation of the argument xml_file results in path traversal. The attack can be initiated remotely. Thโฆ
6.5
CVE-2025-63617 -
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.