6.9

CVSS4.0

CVE-2025-5756 - code-projects Real Estate Property Management System EditCity.php sql injection

A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/EditCity.php. The manipulation leads to sql injection. The attack can be launched remotely. The expl…

πŸ“… Published: June 6, 2025, 10 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

6.9

CVSS4.0

CVE-2025-5755 - SourceCodester Open Source Clinic Management System email_config.php sql injection

A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The e…

πŸ“… Published: June 6, 2025, 9:31 a.m. πŸ”„ Last Modified: June 10, 2025, 3:46 p.m.

8.8

CVSS4.0

CVE-2025-48784 - Soar Cloud HRD Human Resource Management System - Missing Authorization

A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.

πŸ“… Published: June 6, 2025, 9:28 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 2:32 p.m.

8.8

CVSS4.0

CVE-2025-48783 - Soar Cloud HRD Human Resource Management System - External Control of File Name or Path

An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary file paths.

πŸ“… Published: June 6, 2025, 9:27 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 2:36 p.m.

9.9

CVSS4.0

CVE-2025-48782 - Soar Cloud HRD Human Resource Management System - Unrestricted Upload of File with Dangerous Type

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.

πŸ“… Published: June 6, 2025, 9:24 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 2:38 p.m.

8.7

CVSS4.0

CVE-2025-48781 - Soar Cloud HRD Human Resource Management System - External Control of File Name or Path

An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to obtain partial files by specifying arbitrary file paths.

πŸ“… Published: June 6, 2025, 9:21 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 3 p.m.

9.9

CVSS4.0

CVE-2025-48780 - Soar Cloud HRD Human Resource Management System - Deserialization of Untrusted Data

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

πŸ“… Published: June 6, 2025, 9:19 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 3:02 p.m.

9.3

CVSS4.0

CVE-2025-5192 - Soar Cloud HRD Human Resource Management System - Missing Authentication for Critical Function

A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.

πŸ“… Published: June 6, 2025, 9:15 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 2:28 p.m.

8.7

CVSS4.0

CVE-2025-5739 - TOTOLINK X15 HTTP POST Request formSaveConfig buffer overflow

A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate th…

πŸ“… Published: June 6, 2025, 9 a.m. πŸ”„ Last Modified: June 20, 2025, 1:55 p.m.

8.7

CVSS4.0

CVE-2025-5738 - TOTOLINK X15 HTTP POST Request formStats buffer overflow

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The att…

πŸ“… Published: June 6, 2025, 9 a.m. πŸ”„ Last Modified: June 24, 2025, 9:51 a.m.
Total resulsts: 344718
Page 4707 of 34,472
Β« previous page Β» next page
Filters