8.8
CVE-2025-46610 -
ARTEC EMA Mail 6.92 allows CSRF.
9.1
CVE-2024-56524 -
Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.
9.8
CVE-2025-45779 -
Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.
9.8
CVE-2025-44022 -
An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.
5.3
CVE-2025-4552 - ContiNew Admin password unverified password change
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified password change. The attack can be launched remotely. The exploit β¦
5.1
CVE-2025-4551 - ContiNew Admin file cross site scripting
A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The manipulation of the argument File leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been diβ¦
6.9
CVE-2025-4550 - PHPGurukul Apartment Visitors Management System pass-details.php sql injection
A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0. This issue affects some unknown processing of the file /admin/pass-details.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotelyβ¦
6.9
CVE-2025-4549 - Campcodes Online Food Ordering System register-router.php sql injection
A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/register-router.php. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been dβ¦
6.9
CVE-2025-4548 - Campcodes Online Food Ordering System router.php sql injection
A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /routers/router.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been diβ¦
4.8
CVE-2025-4547 - SourceCodester Web-based Pharmacy Product Management System Add User Page cross site scripting
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Add User Page. The manipulation leads to cross site scripting. The attack may be launched remotely. Tβ¦