6.9
CVE-2025-9475 - SourceCodester Human Resource Information System editemployee_process.php unrestricted upload
A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin_Dashboard/process/editemployee_process.php. This manipulation of the argument employee_file201 causes unrestricted upload. The attack may be iβ¦
8.8
CVE-2025-5931 - Dokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege Escalation
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the plugin not properly validating a user's identity prior to updating their password during a staff password reset. This makes it possible for aβ¦
2
CVE-2025-9474 - Mihomo Party Socket sysproxy.ts enableSysProxy temp file
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions. The attack requires a local approach. Thβ¦
6.9
CVE-2025-9473 - SourceCodester Online Bank Management System feedback.php sql injection
A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. This impacts an unknown function of the file /feedback.php. The manipulation of the argument msg leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and β¦
6.9
CVE-2025-9472 - itsourcecode Apartment Management System add_owner_utility.php sql injection
A vulnerability was found in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /owner_utility/add_owner_utility.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made publicβ¦
6.9
CVE-2025-9471 - itsourcecode Apartment Management System add_maintenance_cost.php sql injection
A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been β¦
6.9
CVE-2025-9470 - itsourcecode Apartment Management System add_m_committee.php sql injection
A flaw has been found in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /management/add_m_committee.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
6.9
CVE-2025-9469 - itsourcecode Apartment Management System add_fund.php sql injection
A vulnerability was detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fund/add_fund.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public andβ¦
6.9
CVE-2025-9468 - itsourcecode Apartment Management System add_bill.php sql injection
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /bill/add_bill.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has beβ¦
7.5
CVE-2025-9172 - Vibes <= 2.2.0 - Unauthenticated SQL Injection via `resource` Parameter
The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the βresourceβ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unaβ¦