6.9

CVSS4.0

CVE-2025-7193 - itsourcecode Agri-Trading Online Shopping System suppliercontroller.php sql injection

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/suppliercontroller.php. The manipulation of the argument supplier leads to sql injection. It is possible to launch the attaโ€ฆ

๐Ÿ“… Published: July 8, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: July 11, 2025, 6:44 p.m.

7.5

CVSS3.1

CVE-2025-53355 - mcp-server-kubernetes vulnerable to command injection in several tools

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling aโ€ฆ

๐Ÿ“… Published: July 8, 2025, 7:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7192 - D-Link DIR-645 ssdpcgi cgibin ssdpcgi_main command injection

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed tโ€ฆ

๐Ÿ“… Published: July 8, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: July 14, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2025-37103 - Hardcoded Credential Exposure Allows Unauthorized Access in Web Interface

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

๐Ÿ“… Published: July 8, 2025, 7:09 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-37102 - Authenticated Command Injection Vulnerability In Instant On Command Line Interface

An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileโ€ฆ

๐Ÿ“… Published: July 8, 2025, 7:08 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7191 - code-projects Student Enrollment System login.php sql injection

A vulnerability has been found in code-projects Student Enrollment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been discโ€ฆ

๐Ÿ“… Published: July 8, 2025, 7:02 p.m. ๐Ÿ”„ Last Modified: July 11, 2025, 5:13 p.m.

4.3

CVSS3.1

CVE-2025-27369 - IBM OpenPages with Watson information disclosure

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used for the administration of OpenPages. An authenticated user is able to obtain certain information about system configโ€ฆ

๐Ÿ“… Published: July 8, 2025, 6:43 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:22 a.m.

5.3

CVSS3.1

CVE-2025-27367 - IBM OpenPages with Watson improper input validation

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for data to be saved wiโ€ฆ

๐Ÿ“… Published: July 8, 2025, 6:42 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:23 a.m.

5.3

CVSS3.1

CVE-2024-49783 - IBM OpenPages with Watson information disclosure

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data, they could exploit this vulnerabilityโ€ฆ

๐Ÿ“… Published: July 8, 2025, 6:36 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:21 a.m.

5.3

CVSS3.1

CVE-2024-49784 - IBM OpenPages with Watson information disclosure

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data values โ€ฆ

๐Ÿ“… Published: July 8, 2025, 6:35 p.m. ๐Ÿ”„ Last Modified: Aug. 24, 2025, 11:21 a.m.
Total resulsts: 346554
Page 4458 of 34,656
ยซ previous page ยป next page
Filters