5.3

CVSS4.0

CVE-2025-15014 - loganhong php loganSite Article article_detail.php sql injection

A security flaw has been discovered in loganhong php loganSite up to c035fb5c3edd0b2a5e32fd4051cbbc9e61a31426. This affects an unknown function of the file /includes/article_detail.php of the component Article Handler. Performing manipulation of the argument ID results in sql injection. It is possi…

📅 Published: Dec. 22, 2025, 5:02 a.m. 🔄 Last Modified: Dec. 22, 2025, 5:02 a.m.

4.8

CVSS4.0

CVE-2025-15013 - floooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflow

A vulnerability was identified in floooh sokol up to 5d11344150973f15e16d3ec4ee7550a73fb995e0. The impacted element is the function _sg_validate_pipeline_desc in the library sokol_gfx.h. Such manipulation leads to stack-based buffer overflow. The attack must be carried out locally. The exploit is p…

📅 Published: Dec. 22, 2025, 4:32 a.m. 🔄 Last Modified: Dec. 22, 2025, 4:32 a.m.

6.9

CVSS4.0

CVE-2025-15012 - code-projects Refugee Food Management System home.php sql injection

A vulnerability was determined in code-projects Refugee Food Management System 1.0. The affected element is an unknown function of the file /home/home.php. This manipulation of the argument a causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disc…

📅 Published: Dec. 22, 2025, 4:02 a.m. 🔄 Last Modified: Dec. 22, 2025, 4:02 a.m.

6.9

CVSS4.0

CVE-2025-15011 - code-projects Simple Stock System logout.php sql injection

A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the argument uname results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

📅 Published: Dec. 22, 2025, 3:32 a.m. 🔄 Last Modified: Dec. 22, 2025, 3:32 a.m.

9.3

CVSS4.0

CVE-2025-15016 - Ragic|Enterprise Cloud Database - Hard-coded Cryptographic Key

Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the system as any user.

📅 Published: Dec. 22, 2025, 3:27 a.m. 🔄 Last Modified: Dec. 22, 2025, 3:27 a.m.

8.7

CVSS4.0

CVE-2025-15015 - Ragic|Enterprise Cloud Database - Arbitrary File Read

Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

📅 Published: Dec. 22, 2025, 3:22 a.m. 🔄 Last Modified: Dec. 22, 2025, 3:22 a.m.

9.3

CVSS4.0

CVE-2025-15010 - Tenda WH450 SafeUrlFilter stack-based overflow

A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the publ…

📅 Published: Dec. 22, 2025, 3:02 a.m. 🔄 Last Modified: Dec. 22, 2025, 3:02 a.m.

4

CVSS3.1

CVE-2025-59301 - Modbus/TCP Dos Vulnerability in DVP15MC11T

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

📅 Published: Dec. 22, 2025, 2:56 a.m. 🔄 Last Modified: Dec. 22, 2025, 2:56 a.m.

5.3

CVSS4.0

CVE-2025-15009 - liweiyi ChestnutCMS Filename upload FilenameUtils.getExtension unrestricted upload

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/common/upload of the component Filename Handler. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched …

📅 Published: Dec. 22, 2025, 2:32 a.m. 🔄 Last Modified: Dec. 22, 2025, 2:32 a.m.

6.9

CVSS4.0

CVE-2025-15008 - Tenda WH450 HTTP Request L7Port stack-based overflow

A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public a…

📅 Published: Dec. 22, 2025, 2:02 a.m. 🔄 Last Modified: Dec. 22, 2025, 2:02 a.m.
Total resulsts: 323661
Page 8 of 32,367
« previous page » next page
Filters