6.9

CVSS4.0

CVE-2025-9792 - itsourcecode Apartment Management System e_all_info.php sql injection

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /e_dashboard/e_all_info.php. Such manipulation of the argument mid leads to sql injection. The attack can be executed remotely. The exploit has been dis…

📅 Published: Sept. 1, 2025, 7:32 p.m. 🔄 Last Modified: Sept. 3, 2025, 3:54 p.m.

6.8

CVSS3.1

CVE-2025-9810 - TOCTOU race in Linenoise enables arbitrary file overwrite and permission changes

TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path and subsequent chmod() on the same path.

📅 Published: Sept. 1, 2025, 7:03 p.m. 🔄 Last Modified: April 22, 2026, 4:16 p.m.

8.7

CVSS4.0

CVE-2025-9791 - Tenda AC20 fromAdvSetMacMtuWan stack-based overflow

A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fromAdvSetMacMtuWan. This manipulation of the argument wanMTU causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available …

📅 Published: Sept. 1, 2025, 7:02 p.m. 🔄 Last Modified: Sept. 4, 2025, 4:20 p.m.

8.4

CVSS4.0

CVE-2025-9809 -

Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer.

📅 Published: Sept. 1, 2025, 6:38 p.m. 🔄 Last Modified: Dec. 8, 2025, 3:18 p.m.

6.9

CVSS4.0

CVE-2025-9790 - SourceCodester Hotel Reservation System updateabout.php sql injection

A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the file /admin/updateabout.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit has been released to the public an…

📅 Published: Sept. 1, 2025, 6:32 p.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

7.5

CVSS4.0

CVE-2025-3586 -

In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object ac…

📅 Published: Sept. 1, 2025, 6:07 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

6.9

CVSS4.0

CVE-2025-9789 - SourceCodester Online Hotel Reservation System edituser.php sql injection

A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file /admin/edituser.php. The manipulation of the argument userid leads to sql injection. The attack may be initiated remotely. The exploit is publicly a…

📅 Published: Sept. 1, 2025, 6:02 p.m. 🔄 Last Modified: Nov. 13, 2025, 3:27 p.m.

6.9

CVSS4.0

CVE-2025-9788 - SourceCodester/Campcodes School Log Management System admin_class.php sql injection

A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_class.php. Executing manipulation of the argument id_no can lead to sql injection. The attack can be launched remotely. Th…

📅 Published: Sept. 1, 2025, 5:32 p.m. 🔄 Last Modified: Sept. 3, 2025, 3:56 p.m.

6.9

CVSS4.0

CVE-2025-9375 - xmltodict 0.14.2 - XML Injection

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator,…

📅 Published: Sept. 1, 2025, 4:43 p.m. 🔄 Last Modified: April 22, 2026, 11:30 a.m.

8.7

CVSS4.0

CVE-2025-57799 - StreamVault can perform remote command execution

StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker can modify certain system parameters, construct malicious commands, execute command injection attacks against the system, and ultimately gain server pr…

📅 Published: Sept. 1, 2025, 3:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4062 of 34,919
« previous page » next page
Filters