4.9
CVE-2025-5760 - Simple History <= 5.8.1 - Authenticated (Administrator+) Sensitive Information Exposure via Detectiβ¦
The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sanitization within the append_debug_info_to_context() function in versions prior to 5.8.1. When Detective Mode is enabled, the pluginβs logger captures the entire contents of $_POST β¦
6.9
CVE-2025-5759 - PHPGurukul Local Services Search Engine Management System edit-person-detail.php sql injection
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This vulnerability affects unknown code of the file /admin/edit-person-detail.php?editid=2. The manipulation of the argument editid leads to sql injection. The attack can be initiated β¦
6.9
CVE-2025-5758 - SourceCodester Open Source Clinic Management System doctor.php sql injection
A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This affects an unknown part of the file /doctor.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit hasβ¦
5.1
CVE-2025-5757 - code-projects Traffic Offense Reporting System save-reported.php cross site scripting
A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /save-reported.php. The manipulation of the argument offence_id/vehicle_no/driver_license/name/address/gender/officer_rβ¦
6.9
CVE-2025-5756 - code-projects Real Estate Property Management System EditCity.php sql injection
A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/EditCity.php. The manipulation leads to sql injection. The attack can be launched remotely. The explβ¦
6.9
CVE-2025-5755 - SourceCodester Open Source Clinic Management System email_config.php sql injection
A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The eβ¦
8.8
CVE-2025-48784 - Soar Cloud HRD Human Resource Management System - Missing Authorization
A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.
8.8
CVE-2025-48783 - Soar Cloud HRD Human Resource Management System - External Control of File Name or Path
An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary file paths.
9.9
CVE-2025-48782 - Soar Cloud HRD Human Resource Management System - Unrestricted Upload of File with Dangerous Type
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.
8.7
CVE-2025-48781 - Soar Cloud HRD Human Resource Management System - External Control of File Name or Path
An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to obtain partial files by specifying arbitrary file paths.