7.3
CVE-2025-7405 - Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC …
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not ha…
6.9
CVE-2025-9759 - Campcodes/SourceCodester Courier Management System ajax.php signup sql injection
A security flaw has been discovered in Campcodes/SourceCodester Courier Management System 1.0. Affected by this issue is the function Signup of the file /ajax.php. Performing manipulation of the argument lastname results in sql injection. It is possible to initiate the attack remotely. The exploit …
5.3
CVE-2025-9758 - deepakmisal24 Chemical Inventory Management System inventory_form.php sql injection
A vulnerability was identified in deepakmisal24 Chemical Inventory Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory_form.php. Such manipulation of the argument chem_name leads to sql injection. The attack may be performed from remote. Th…
6.9
CVE-2025-9570 - Sunnet|eHRD CTMS - Arbitrary File Reading through Path Traversal
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
5.1
CVE-2025-9569 - Sunnet|eHRD CTMS - Reflected Cross-site Scripting
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
5.1
CVE-2025-9568 - Sunnet|eHRD CTMS - Reflected Cross-site Scripting
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
5.1
CVE-2025-9567 - Sunnet|eHRD CTMS - Reflected Cross-site Scripting
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
6.9
CVE-2025-9757 - Campcodes/SourceCodester Courier Management System ajax.php login sql injection
A vulnerability was determined in Campcodes/SourceCodester Courier Management System 1.0. Affected is the function Login of the file /ajax.php. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed an…
5.3
CVE-2025-9756 - PHPGurukul User Management System change-emailid.php sql injection
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
5.3
CVE-2025-9755 - Khanakag-17 Library Management System index.php cross site scripting
A vulnerability has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of the argument msg leads to cross site scripting. Remote exploitation of the attack is possible. The exp…