6.8
CVE-2025-3705 - OS Command Injection via USB Config Load
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive.
9.1
CVE-2025-3626 - OS Command Injection via Config Upload in WebUI
A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.
5.3
CVE-2025-7121 - Campcodes Complaint Management System complaint-details.php sql injection
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/complaint-details.php. The manipulation of the argument cid leads to sql injection. It is possible to initiate the attack remotely. The exploitβ¦
6.9
CVE-2025-7120 - Campcodes Complaint Management System check_availability.php sql injection
A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /users/check_availability.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The β¦
8.5
CVE-2025-3920 - Hard-coded Password in SUR-FBD CMMS
A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the application's installation directory could extractβ¦
6.9
CVE-2025-7119 - Campcodes Complaint Management System index.php sql injection
A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /users/index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. Theβ¦
0.0
CVE-2025-53614 -
Not used
0.0
CVE-2025-53617 -
Not used
0.0
CVE-2025-53615 -
Not used
0.0
CVE-2025-53616 -
Not used