6.9

CVSS4.0

CVE-2025-10832 - SourceCodester Pet Grooming Management Software fetch_product_details.php sql injection

A vulnerability was found in SourceCodester Pet Grooming Management Software 1.0. The affected element is an unknown function of the file /admin/fetch_product_details.php. The manipulation of the argument barcode results in sql injection. The attack may be performed from remote. The exploit has bee…

πŸ“… Published: Sept. 23, 2025, 2:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:07 p.m.

4.3

CVSS3.1

CVE-2025-42907 - Server-Side Request Forgery in SAP BI Platform

SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system.

πŸ“… Published: Sept. 23, 2025, 1:58 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10831 - Campcodes Computer Sales and Inventory System pro_edit1.php sql injection

A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. The manipulation of the argument prodcode leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed …

πŸ“… Published: Sept. 23, 2025, 1:32 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:07 p.m.

6.9

CVSS4.0

CVE-2025-10830 - Campcodes Computer Sales and Inventory System inv_edit1.php sql injection

A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/inv_edit1.php. Executing manipulation of the argument idd can lead to sql injection. The attack can be executed remotely. The exploit has been published and may …

πŸ“… Published: Sept. 23, 2025, 1:32 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:08 p.m.

8.7

CVSS4.0

CVE-2025-9495 - Viessmann Vitogate 300 Authentication Bypass

The Vitogate 300 web interface fails to enforce proper server-side authentication and relies on frontend-based authentication controls. This allows an attacker to simply modify HTML elements in the browser’s developer tools to bypass login restrictions. By removing specific UI elements, an attacker…

πŸ“… Published: Sept. 23, 2025, 1:16 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-9494 - Viessmann Vitogate 300 OS Command Injection

An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected installations. Specifically, the `/cgi-bin/vitogate.cgi` endpoint is affected, when the `form` JSON parameter is set to `form-0-2`. The vulnerability stems…

πŸ“… Published: Sept. 23, 2025, 1:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10829 - Campcodes Computer Sales and Inventory System sup_edit1.php sql injection

A vulnerability was detected in Campcodes Computer Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/sup_edit1.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public …

πŸ“… Published: Sept. 23, 2025, 1:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:08 p.m.

5.3

CVSS4.0

CVE-2025-10828 - SourceCodester Pet Grooming Management Software edit.php sql injection

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file /admin/edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and …

πŸ“… Published: Sept. 23, 2025, 1:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:08 p.m.

5.3

CVSS4.0

CVE-2025-10827 - PHPJabbers Restaurant Menu Maker preview.php cross site scripting

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available…

πŸ“… Published: Sept. 23, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:08 p.m.

5.3

CVSS4.0

CVE-2025-10826 - Campcodes Online Beauty Parlor Management System sales-reports-detail.php sql injection

A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate results in sql injection. The attack can be launched …

πŸ“… Published: Sept. 23, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:08 p.m.
Total resulsts: 349182
Page 3712 of 34,919
Β« previous page Β» next page
Filters