6.9

CVSS4.0

CVE-2025-10668 - itsourcecode Online Discussion Forum compose_msg_admin.php sql injection

A security vulnerability has been detected in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file /members/compose_msg_admin.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publi…

📅 Published: Sept. 18, 2025, 1:32 p.m. 🔄 Last Modified: Sept. 19, 2025, 8:12 p.m.

6.9

CVSS4.0

CVE-2025-10667 - itsourcecode Online Discussion Forum compose_msg.php sql injection

A weakness has been identified in itsourcecode Online Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /members/compose_msg.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been m…

📅 Published: Sept. 18, 2025, 1:02 p.m. 🔄 Last Modified: Sept. 20, 2025, 2:35 a.m.

8.7

CVSS4.0

CVE-2025-10666 - D-Link DIR-825 apply.cgi sub_4106d4 buffer overflow

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the pu…

📅 Published: Sept. 18, 2025, 1:02 p.m. 🔄 Last Modified: Feb. 3, 2026, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-10665 - kidaze CourseSelectionSystem COUNT3s3.php sql injection

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Affected is an unknown function of the file /Profilers/PProfile/COUNT3s3.php. The manipulation of the argument csem leads to sql injection. Remote exploitation of the attack is possible. T…

📅 Published: Sept. 18, 2025, 12:02 p.m. 🔄 Last Modified: Oct. 8, 2025, 5:07 p.m.

6.9

CVSS4.0

CVE-2025-10664 - PHPGurukul Small CRM create-ticket.php sql injection

A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.php. Executing manipulation of the argument subject can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

📅 Published: Sept. 18, 2025, 12:02 p.m. 🔄 Last Modified: Sept. 19, 2025, 8:25 p.m.

9.8

CVSS3.1

CVE-2024-13151 - SQLi in ESBI Informatics's Auto Service Software

CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection.This issue affects Auto Service Software: before v.2025.10.01.

📅 Published: Sept. 18, 2025, 11:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-40678 - Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload a dangerous file type by sending a POST request using the parameter “cctl00$ContentPlaceHolder1$fuAdjunto” in “/MemberPages/ntf_absentismo.aspx”.

📅 Published: Sept. 18, 2025, 11:47 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-40677 - SQL injection vulnerability in Summar Software´s Portal del Empleado

SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve, create, update, and delete the database by sending a POST request using the parameter “ctl00$ContentPlaceHolder1$filtroNombre” in “/MemberPages/quienesquien.aspx”.

📅 Published: Sept. 18, 2025, 11:46 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-25011 - Ericsson Catalog Manager and Ericsson Order Care - Exposure of Sensitive Information Vulnerability

Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue.

📅 Published: Sept. 18, 2025, 11:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-10207 - Authenticated File Disclosure/Delete

Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.

📅 Published: Sept. 18, 2025, 11:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3781 of 34,919
« previous page » next page
Filters