7.2

CVSS3.1

CVE-2025-1929 - SQLi in RiskTurk's Treasury Management Software

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılı…

📅 Published: Aug. 15, 2025, 12:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9051 - projectworlds Travel Management System updatecategory.php sql injection

A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /updatecategory.php. The manipulation of the argument t1 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the …

📅 Published: Aug. 15, 2025, 12:02 p.m. 🔄 Last Modified: Aug. 18, 2025, 3:08 p.m.

8.7

CVSS4.0

CVE-2025-54475 - Extension - joomsky.com - SQL injection in JS jobs component version 1.3.2 - 1.4.4 for Joomla

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

📅 Published: Aug. 15, 2025, 11:54 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-54474 - Extension - dj-extensions.com - SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joo…

A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

📅 Published: Aug. 15, 2025, 11:54 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-54473 - Extension - phoca.cz - Authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and…

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

📅 Published: Aug. 15, 2025, 11:54 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9050 - projectworlds Travel Management System addcategory.php sql injection

A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /addcategory.php. The manipulation of the argument t1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the pu…

📅 Published: Aug. 15, 2025, 11:32 a.m. 🔄 Last Modified: Aug. 18, 2025, 3:09 p.m.

6.9

CVSS4.0

CVE-2025-9047 - projectworlds Visitor Management System visitor_out.php sql injection

A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /visitor_out.php. The manipulation of the argument rid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma…

📅 Published: Aug. 15, 2025, 11:02 a.m. 🔄 Last Modified: Aug. 18, 2025, 3:09 p.m.

8.7

CVSS4.0

CVE-2025-9046 - Tenda AC20 setMacFilterCfg sub_46A2AC stack-based overflow

A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the pub…

📅 Published: Aug. 15, 2025, 11:02 a.m. 🔄 Last Modified: Aug. 18, 2025, 3:10 p.m.

5.7

CVSS3.1

CVE-2025-26709 - Unauthorized Access Vulnerability in ZTE F50

There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface

📅 Published: Aug. 15, 2025, 10:35 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9028 - code-projects Online Medicine Guide adphar.php sql injection

A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /adphar.php. Executing manipulation of the argument phuname can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

📅 Published: Aug. 15, 2025, 10:32 a.m. 🔄 Last Modified: Sept. 26, 2025, 12:31 p.m.
Total resulsts: 349182
Page 4259 of 34,919
« previous page » next page
Filters