7

CVSS4.0

CVE-2025-13283 - Chunghwa Telecom|TenderDocTransfer - Arbitrary File Copy and Paste

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could u…

📅 Published: Nov. 17, 2025, 3:30 a.m. 🔄 Last Modified: Dec. 19, 2025, 5:01 p.m.

7

CVSS4.0

CVE-2025-13282 - Chunghwa Telecom|TenderDocTransfer - Arbitrary File Delete

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these …

📅 Published: Nov. 17, 2025, 3:24 a.m. 🔄 Last Modified: Dec. 19, 2025, 5:02 p.m.

5.3

CVSS4.0

CVE-2025-13260 - Campcodes Supplier Management System edit_product.php sql injection

A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument cmbProductUnit leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to th…

📅 Published: Nov. 17, 2025, 3:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

9.4

CVSS4.0

CVE-2025-10460 - Unsanitized parameter input leading to SQL Injection vulnerability

A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows an unauthorised user to retrieve sensitive database contents via unsanitized parameter input. This vulnerability occurs due to improper input validati…

📅 Published: Nov. 17, 2025, 2:48 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-13259 - Campcodes Supplier Management System edit_unit.php sql injection

A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

📅 Published: Nov. 17, 2025, 2:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

8.7

CVSS4.0

CVE-2025-13258 - Tenda AC20 WifiExtraSet buffer overflow

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is an unknown function of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

📅 Published: Nov. 17, 2025, 2:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:30 a.m.

6.9

CVSS4.0

CVE-2025-13257 - itsourcecode Inventory Management System index.php sql injection

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been…

📅 Published: Nov. 17, 2025, 1:32 a.m. 🔄 Last Modified: Nov. 19, 2025, 1:16 p.m.

5.3

CVSS4.0

CVE-2025-13256 - projectworlds Advanced Library Management System borrow.php sql injection

A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of the argument roll_number can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made av…

📅 Published: Nov. 17, 2025, 1:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2025-13255 - projectworlds Advanced Library Management System book_search.php sql injection

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a manipulation of the argument book_pub/book_title results in sql injection. It is possible to initiate the attack remotel…

📅 Published: Nov. 17, 2025, 12:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2025-13254 - projectworlds Advanced Library Management System add_member.php sql injection

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be performed from remote. The exploit is publicly availab…

📅 Published: Nov. 17, 2025, 12:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:29 a.m.
Total resulsts: 349182
Page 2996 of 34,919
« previous page » next page
Filters