5.3

CVSS4.0

CVE-2025-2671 - Yue Lao Blind Box 月老盲盒 Upload.php base64image unrestricted upload

A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64image of the file /app/controller/Upload.php. The manipulation of the argument data leads to unrestricted upload. The attack can be initiated remotely. The …

📅 Published: March 23, 2025, 10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-2665 - PHPGurukul Online Security Guards Hiring System bwdates-reports-details.php sql injection

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the …

📅 Published: March 23, 2025, 9:31 p.m. 🔄 Last Modified: May 13, 2025, 8:03 p.m.

5.1

CVSS4.0

CVE-2025-2664 - CodeZips Hospital Management System suadpeted.php sql injection

A vulnerability was found in CodeZips Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /suadpeted.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been dis…

📅 Published: March 23, 2025, 9 p.m. 🔄 Last Modified: May 13, 2025, 8:10 p.m.

6.9

CVSS4.0

CVE-2025-2663 - PHPGurukul Bank Locker Management System search-locker-details.php sql injection

A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /search-locker-details.php. The manipulation of the argument searchinput leads to sql injection. The attack can be launch…

📅 Published: March 23, 2025, 8:31 p.m. 🔄 Last Modified: May 13, 2025, 8:13 p.m.

5.3

CVSS4.0

CVE-2025-2662 - Project Worlds Online Time Table Generator studentdashboard.php sql injection

A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file student/studentdashboard.php. The manipulation of the argument course leads to sql injection. It is possible to launch the attack remotely. Th…

📅 Published: March 23, 2025, 8 p.m. 🔄 Last Modified: July 9, 2025, 1:02 a.m.

6.9

CVSS4.0

CVE-2025-2661 - Project Worlds Online Time Table Generator index.php sql injection

A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /staff/index.php. The manipulation of the argument e leads to sql injection. The attack may be initiated remotely. The exploit has been disc…

📅 Published: March 23, 2025, 7:31 p.m. 🔄 Last Modified: July 9, 2025, 1:11 a.m.

6.9

CVSS4.0

CVE-2025-2660 - Project Worlds Online Time Table Generator index.php sql injection

A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. The attack can be initiated remotely. The exploit has been di…

📅 Published: March 23, 2025, 7 p.m. 🔄 Last Modified: July 9, 2025, 1:19 a.m.

6.9

CVSS4.0

CVE-2025-2659 - Project Worlds Online Time Table Generator index.php sql injection

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is possible to initiate the attack remotely. The exploit has bee…

📅 Published: March 23, 2025, 6:31 p.m. 🔄 Last Modified: July 9, 2025, 1:23 a.m.

6.9

CVSS4.0

CVE-2025-2658 - PHPGurukul Online Security Guards Hiring System search-request.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown functionality of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launc…

📅 Published: March 23, 2025, 6 p.m. 🔄 Last Modified: May 13, 2025, 8:14 p.m.

6.9

CVSS4.0

CVE-2025-2657 - projectworlds Apartment Visitors Management System front.php sql injection

A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /front.php. The manipulation of the argument rid leads to sql injection. The attack can be launched remotely. The exploi…

📅 Published: March 23, 2025, 5:31 p.m. 🔄 Last Modified: May 13, 2025, 8:18 p.m.
Total resulsts: 349182
Page 6247 of 34,919
« previous page » next page
Filters