6.9
CVE-2025-2062 - projectworlds Life Insurance Management System clientStatus.php sql injection
A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument client_id leads to sql injection. It is possible to launch the attack remotely. The exploit haβ¦
5.3
CVE-2025-2061 - code-projects Online Ticket Reservation System passenger.php cross site scripting
A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /passenger.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exβ¦
4.2
CVE-2025-26708 - ZTELink has a configuration defect vulnerability
There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service.
6.9
CVE-2025-2060 - PHPGurukul Emergency Ambulance Hiring Portal admin-profile.php sql injection
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible to initiate the attack remotelyβ¦
6.9
CVE-2025-2059 - PHPGurukul Emergency Ambulance Hiring Portal booking-details.php sql injection
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/booking-details.php. The manipulation of the argument ambulanceregnum leads to sql injection. The attack may be launched β¦
4.3
CVE-2025-0748 - Homey <= 2.4.3 - Cross-Site Request Forgery to User Verification
The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the 'homey_verify_user_manually' function. This makes it possible for unauthenticated attackers to update verify an user via a fβ¦
4.3
CVE-2024-13526 - EventPrime β Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticaβ¦
The EventPrime β Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, β¦
8.1
CVE-2025-0749 - Homey <= 2.4.3 - Limited Authentication Bypass due to Missing Empty Value Check
The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers toβ¦
6.9
CVE-2025-2058 - PHPGurukul Emergency Ambulance Hiring Portal search.php sql injection
A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remβ¦
6.9
CVE-2025-2057 - PHPGurukul Emergency Ambulance Hiring Portal about-us.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. It is possible to launch the attack remotely. The exploβ¦