7.5

CVSS3.1

CVE-2025-12482 - Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via…

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu…

📅 Published: Nov. 16, 2025, 4:17 a.m. 🔄 Last Modified: Nov. 16, 2025, 4:17 a.m.

5.3

CVSS4.0

CVE-2025-13236 - itsourcecode Inventory Management System index.php sql injection

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and m…

📅 Published: Nov. 16, 2025, 4:02 a.m. 🔄 Last Modified: Nov. 16, 2025, 4:02 a.m.

6.9

CVSS4.0

CVE-2025-13235 - itsourcecode Inventory Management System login.php sql injection

A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly dis…

📅 Published: Nov. 16, 2025, 3:32 a.m. 🔄 Last Modified: Nov. 16, 2025, 3:32 a.m.

5.3

CVSS4.0

CVE-2025-13234 - itsourcecode Inventory Management System index.php sql injection

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made …

📅 Published: Nov. 16, 2025, 3:02 a.m. 🔄 Last Modified: Nov. 16, 2025, 3:02 a.m.

6.9

CVSS4.0

CVE-2025-13233 - itsourcecode Inventory Management System index.php sql injection

A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to t…

📅 Published: Nov. 16, 2025, 2:32 a.m. 🔄 Last Modified: Nov. 16, 2025, 2:32 a.m.

5.1

CVSS4.0

CVE-2025-13232 - projectsend File Editor/Custom Download Aliases cross site scripting

A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to vers…

📅 Published: Nov. 16, 2025, 1:02 a.m. 🔄 Last Modified: Nov. 16, 2025, 1:02 a.m.

6.9

CVSS4.0

CVE-2025-13221 - Intelbras UnniTI usuarios.xml credentials storage

A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has b…

📅 Published: Nov. 15, 2025, 7:32 p.m. 🔄 Last Modified: Nov. 15, 2025, 7:32 p.m.

5.1

CVSS4.0

CVE-2025-13210 - itsourcecode Inventory Management System index.php sql injection

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the argument PROMODEL leads to sql injection. The attack may be performed from remote. The exploit has be…

📅 Published: Nov. 15, 2025, 7:02 p.m. 🔄 Last Modified: Nov. 15, 2025, 7:02 p.m.

5.3

CVSS4.0

CVE-2025-13209 - bestfeng oa_git_free WorkflowPredefineController.java updateWriteBack xml external entity reference

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity refere…

📅 Published: Nov. 15, 2025, 6:32 p.m. 🔄 Last Modified: Nov. 15, 2025, 6:32 p.m.

5.3

CVSS4.0

CVE-2025-13208 - FantasticLBP Hotels Server hotelList.php sql injection

A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The manipulation of the argument subjectId/cityName results in sql injection. The attack can be exe…

📅 Published: Nov. 15, 2025, 6:02 p.m. 🔄 Last Modified: Nov. 15, 2025, 6:02 p.m.
Total resulsts: 318420
Page 3 of 31,842
« previous page » next page
Filters