8.7

CVSS4.0

CVE-2025-6487 - TOTOLINK A3002R formRoute stack-based overflow

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm/formRoute. The manipulation of the argument subnet leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit …

πŸ“… Published: June 22, 2025, 6 p.m. πŸ”„ Last Modified: July 7, 2025, 6:50 p.m.

8.7

CVSS4.0

CVE-2025-6486 - TOTOLINK A3002R formWlanMultipleAP stack-based overflow

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP of the file /boafrm/formWlanMultipleAP. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be…

πŸ“… Published: June 22, 2025, 5:31 p.m. πŸ”„ Last Modified: July 7, 2025, 6:49 p.m.

5.3

CVSS4.0

CVE-2025-6485 - TOTOLINK A3002R formWlSiteSurvey os command injection

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. It is possible to initiate the attack remote…

πŸ“… Published: June 22, 2025, 5 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 8:27 p.m.

5.1

CVSS4.0

CVE-2025-6484 - code-projects Online Shopping Store action.php sql injection

A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql injection. The attack may be launched remote…

πŸ“… Published: June 22, 2025, 4:31 p.m. πŸ”„ Last Modified: July 11, 2025, 12:13 p.m.

6.9

CVSS4.0

CVE-2025-6483 - code-projects Simple Pizza Ordering System edituser.php sql injection

A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exp…

πŸ“… Published: June 22, 2025, 4 p.m. πŸ”„ Last Modified: June 25, 2025, 7:01 p.m.

6.9

CVSS4.0

CVE-2025-6482 - code-projects Simple Pizza Ordering System edituser-exec.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit h…

πŸ“… Published: June 22, 2025, 3:31 p.m. πŸ”„ Last Modified: June 25, 2025, 7:05 p.m.

6.9

CVSS4.0

CVE-2025-6481 - code-projects Simple Pizza Ordering System update.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has …

πŸ“… Published: June 22, 2025, 3 p.m. πŸ”„ Last Modified: June 25, 2025, 7:17 p.m.

6.9

CVSS4.0

CVE-2025-6480 - code-projects Simple Pizza Ordering System addcatexec.php sql injection

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /addcatexec.php. The manipulation of the argument textfield leads to sql injection. The attack can be initiated remotely. The exploit has been disc…

πŸ“… Published: June 22, 2025, 2:31 p.m. πŸ”„ Last Modified: June 25, 2025, 7:18 p.m.

6.9

CVSS4.0

CVE-2025-6479 - code-projects Simple Pizza Ordering System salesreport.php sql injection

A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /salesreport.php. The manipulation of the argument dayfrom leads to sql injection. It is possible to initiate the attack remotely. The exploit has been d…

πŸ“… Published: June 22, 2025, 2 p.m. πŸ”„ Last Modified: June 25, 2025, 7:19 p.m.

5.3

CVSS4.0

CVE-2025-6478 - CodeAstro Expense Management System cross-site request forgery

A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely.

πŸ“… Published: June 22, 2025, 1:31 p.m. πŸ”„ Last Modified: June 27, 2025, 5:13 p.m.
Total resulsts: 349182
Page 4920 of 34,919
Β« previous page Β» next page
Filters