5.3

CVSS4.0

CVE-2025-9400 - YiFang CMS P_file.php mergeMultipartUpload unrestricted upload

A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation of the argument File causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be u…

πŸ“… Published: Aug. 25, 2025, 12:32 a.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:45 p.m.

5.3

CVSS4.0

CVE-2025-9399 - YiFang CMS L_tool.php sql injection

A vulnerability was detected in YiFang CMS up to 2.0.5. Affected by this issue is some unknown functionality of the file app/logic/L_tool.php. The manipulation of the argument new_url results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. The vendo…

πŸ“… Published: Aug. 25, 2025, 12:02 a.m. πŸ”„ Last Modified: Dec. 11, 2025, 6:47 p.m.

7.2

CVSS3.1

CVE-2025-29516 -

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 2, 2025, 6:17 p.m.

7.5

CVSS3.1

CVE-2025-29420 -

PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 8:59 p.m.

6.5

CVSS3.1

CVE-2025-29522 -

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 2, 2025, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-56212 - SQL Injection in Hospital Management System's Doctor Addition Feature

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: April 28, 2026, 11 a.m.

9.8

CVSS3.1

CVE-2025-56214 - SQL Injection via Username Parameter in phpGurukul Hospital Management System 4.0

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: April 22, 2026, 10:30 p.m.

5.4

CVSS3.1

CVE-2025-52130 -

File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote code execution (RCE…

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-56215 - SQL Injection via pagetitle parameter in Hospital Management System 4.0

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: April 22, 2026, 10:30 p.m.

6.1

CVSS3.1

CVE-2025-55574 -

Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 7:44 p.m.
Total resulsts: 349182
Page 4151 of 34,919
Β« previous page Β» next page
Filters