4.8
CVE-2025-6490 - sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow
A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approacβ¦
6.9
CVE-2025-6489 - itsourcecode Agri-Trading Online Shopping System transactionsave.php sql injection
A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploitβ¦
8.7
CVE-2025-6487 - TOTOLINK A3002R formRoute stack-based overflow
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm/formRoute. The manipulation of the argument subnet leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit β¦
8.7
CVE-2025-6486 - TOTOLINK A3002R formWlanMultipleAP stack-based overflow
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP of the file /boafrm/formWlanMultipleAP. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can beβ¦
5.3
CVE-2025-6485 - TOTOLINK A3002R formWlSiteSurvey os command injection
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. It is possible to initiate the attack remoteβ¦
5.1
CVE-2025-6484 - code-projects Online Shopping Store action.php sql injection
A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql injection. The attack may be launched remoteβ¦
6.9
CVE-2025-6483 - code-projects Simple Pizza Ordering System edituser.php sql injection
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The expβ¦
6.9
CVE-2025-6482 - code-projects Simple Pizza Ordering System edituser-exec.php sql injection
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit hβ¦
6.9
CVE-2025-6481 - code-projects Simple Pizza Ordering System update.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has β¦
6.9
CVE-2025-6480 - code-projects Simple Pizza Ordering System addcatexec.php sql injection
A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /addcatexec.php. The manipulation of the argument textfield leads to sql injection. The attack can be initiated remotely. The exploit has been discβ¦