6.9

CVSS4.0

CVE-2025-10102 - code-projects Online Event Judging System index.php sql injection

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released …

📅 Published: Sept. 8, 2025, 6:32 p.m. 🔄 Last Modified: Nov. 13, 2025, 3:59 p.m.

9.8

CVSS3.1

CVE-2025-9114 - Doccure <= 1.5.0 - Unauthenticated Arbitrary User Password Change

The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated…

📅 Published: Sept. 8, 2025, 6:23 p.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

9.8

CVSS3.1

CVE-2025-9113 - Doccure Core <= 1.5.3 - Unauthenticated Arbitrary File Upload

The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' function in all versions up to, and including, 1.5.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affecte…

📅 Published: Sept. 8, 2025, 6:23 p.m. 🔄 Last Modified: April 21, 2026, 3:15 a.m.

8.8

CVSS3.1

CVE-2025-9112 - Doccure <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Upload

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to…

📅 Published: Sept. 8, 2025, 6:23 p.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

6.9

CVSS4.0

CVE-2025-10100 - SourceCodester Simple Forum Discussion System admin_class.php sql injection

A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is no…

📅 Published: Sept. 8, 2025, 6:02 p.m. 🔄 Last Modified: Sept. 12, 2025, 8:47 p.m.

4.8

CVSS4.0

CVE-2025-10099 - Portabilis i-Educar Editar usuário educar_usuario_cad.php cross site scripting

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of the component Editar usuário Page. This manipulation of the argument email/data_inicial/data_expiracao causes cross site scrip…

📅 Published: Sept. 8, 2025, 5:32 p.m. 🔄 Last Modified: Sept. 11, 2025, 3:39 p.m.

5.3

CVSS4.0

CVE-2025-10098 - PHPGurukul User Management System edit-user-profile.php sql injection

A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from remote. The exploit has been released to the public…

📅 Published: Sept. 8, 2025, 5:02 p.m. 🔄 Last Modified: Oct. 15, 2025, 3:59 p.m.

5.3

CVSS4.0

CVE-2025-10097 - SimStudioAI sim route.ts code injection

A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.ts. The manipulation of the argument code leads to code injection. The attack is possible to be carried out remotely.

📅 Published: Sept. 8, 2025, 4:32 p.m. 🔄 Last Modified: March 10, 2026, 3:08 p.m.

5.3

CVSS4.0

CVE-2025-10096 - SimStudioAI sim route.ts server-side request forgery

A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app/api/files/parse/route.ts. Executing manipulation of the argument filePath can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publi…

📅 Published: Sept. 8, 2025, 3:32 p.m. 🔄 Last Modified: Nov. 14, 2025, 8:32 p.m.

7.5

CVSS3.1

CVE-2025-40930 - JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfau…

JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact.

📅 Published: Sept. 8, 2025, 3:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3962 of 34,919
« previous page » next page
Filters