8.7

CVSS4.0

CVE-2025-12622 - Tenda AC10 SysRunCmd formSysRunCmd buffer overflow

A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and mayโ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 7:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:23 a.m.

8.7

CVSS4.0

CVE-2025-12619 - Tenda A15 openNetworkGateway fromSetWirelessRepeat buffer overflow

A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could bโ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 7:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:23 a.m.

7.1

CVSS4.0

CVE-2025-12503 - Digiwin๏ฝœEasyFlow .NET and EasyFlow AiNet

EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

๐Ÿ“… Published: Nov. 3, 2025, 6:51 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-12618 - Tenda AC8 DatabaseIniSet buffer overflow

A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Nov. 3, 2025, 6:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:23 a.m.

6.9

CVSS4.0

CVE-2025-12617 - itsourcecode Billing System login_crud.php sql injection

A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument Password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Nov. 3, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

6.3

CVSS4.0

CVE-2025-12616 - PHPGurukul News Portal settings.py insertion of sensitive information into debugging code

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexityโ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

2.3

CVSS4.0

CVE-2025-12615 - PHPGurukul News Portal settings.py hard-coded key

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requiโ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 3:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:22 a.m.

5.1

CVSS4.0

CVE-2025-12614 - SourceCodester Best House Rental Management System admin_class.php delete_payment sql injection

A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made avaโ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Nov. 5, 2025, 6:55 p.m.

5.3

CVSS4.0

CVE-2025-12612 - Campcodes School Fees Payment Management System ajax.php sql injection

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

8.7

CVSS4.0

CVE-2025-12611 - Tenda AC21 SetPptpServerCfg formSetPPTPServer buffer overflow

A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly availabโ€ฆ

๐Ÿ“… Published: Nov. 3, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:21 a.m.
Total resulsts: 349182
Page 3179 of 34,919
ยซ previous page ยป next page
Filters