4.8

CVSS4.0

CVE-2025-6490 - sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow

A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based buffer overflow. An attack has to be approac…

πŸ“… Published: June 22, 2025, 7 p.m. πŸ”„ Last Modified: June 30, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-6489 - itsourcecode Agri-Trading Online Shopping System transactionsave.php sql injection

A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit…

πŸ“… Published: June 22, 2025, 6:31 p.m. πŸ”„ Last Modified: June 25, 2025, 7:31 p.m.

8.7

CVSS4.0

CVE-2025-6487 - TOTOLINK A3002R formRoute stack-based overflow

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm/formRoute. The manipulation of the argument subnet leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit …

πŸ“… Published: June 22, 2025, 6 p.m. πŸ”„ Last Modified: July 7, 2025, 6:50 p.m.

8.7

CVSS4.0

CVE-2025-6486 - TOTOLINK A3002R formWlanMultipleAP stack-based overflow

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP of the file /boafrm/formWlanMultipleAP. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be…

πŸ“… Published: June 22, 2025, 5:31 p.m. πŸ”„ Last Modified: July 7, 2025, 6:49 p.m.

5.3

CVSS4.0

CVE-2025-6485 - TOTOLINK A3002R formWlSiteSurvey os command injection

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. It is possible to initiate the attack remote…

πŸ“… Published: June 22, 2025, 5 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:27 p.m.

5.1

CVSS4.0

CVE-2025-6484 - code-projects Online Shopping Store action.php sql injection

A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql injection. The attack may be launched remote…

πŸ“… Published: June 22, 2025, 4:31 p.m. πŸ”„ Last Modified: July 11, 2025, 12:13 p.m.

6.9

CVSS4.0

CVE-2025-6483 - code-projects Simple Pizza Ordering System edituser.php sql injection

A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exp…

πŸ“… Published: June 22, 2025, 4 p.m. πŸ”„ Last Modified: June 25, 2025, 7:01 p.m.

6.9

CVSS4.0

CVE-2025-6482 - code-projects Simple Pizza Ordering System edituser-exec.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit h…

πŸ“… Published: June 22, 2025, 3:31 p.m. πŸ”„ Last Modified: June 25, 2025, 7:05 p.m.

6.9

CVSS4.0

CVE-2025-6481 - code-projects Simple Pizza Ordering System update.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has …

πŸ“… Published: June 22, 2025, 3 p.m. πŸ”„ Last Modified: June 25, 2025, 7:17 p.m.

6.9

CVSS4.0

CVE-2025-6480 - code-projects Simple Pizza Ordering System addcatexec.php sql injection

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /addcatexec.php. The manipulation of the argument textfield leads to sql injection. The attack can be initiated remotely. The exploit has been disc…

πŸ“… Published: June 22, 2025, 2:31 p.m. πŸ”„ Last Modified: June 25, 2025, 7:18 p.m.
Total resulsts: 343970
Page 4399 of 34,397
Β« previous page Β» next page
Filters