Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-9803

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for ensuring the token is intended for the application. This oversight allows attackers to use tokens issued to malicious applications to gain unauthorized access to user accounts. The issue is resolved in version 1.9.35.

PUBLISHED
Vendor
lunary-ai
Product
lunary-ai/lunary
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9802

A vulnerability was detected in RemoteClinic 2.0. This vulnerability affects unknown code of the file /staff/profile.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely.

PUBLISHED
Vendor
n/a
Product
RemoteClinic
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9801

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePath leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The identifier of the patch is 45372aece5e05e0

PUBLISHED
Vendor
SimStudioAI
Product
sim
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9800

A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of the file apps/sim/app/api/files/upload/route.ts of the component HTML File Parser. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. This product operates on a rolling release basis, ensuring continuous delivery. Co

PUBLISHED
Vendor
SimStudioAI
Product
sim
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9799

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
n/a
Product
Langfuse
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2025-9798

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS. This issue affects Netigma: from 6.3.3 before 6.3.5 V8.

PUBLISHED
Vendor
Netcad Software Inc.
Product
Netigma
Provider severity
HIGH
Conflicts
0

CVE-2025-9797

A vulnerability was determined in mrvautin expressCart up to b31302f4e99c3293bd742c6d076a721e168118b0. This impacts an unknown function of the file /admin/product/edit/ of the component Edit Product Page. This manipulation causes injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

PUBLISHED
Vendor
mrvautin
Product
expressCart
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9796

A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/main/java/com/jeesite/common/codec/EncodeUtils.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 5.13.0 mitigates this issue. The patch is identified as 63773c97a56bdb3649510e83b66c16db4754965b. Upgrading the affected component is recommended.

PUBLISHED
Vendor
thinkgem
Product
JeeSite
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9795

A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
xujeff
Product
tianti 天梯
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9794

A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/pos_transac.php?action=add. Executing manipulation of the argument cash/firstname can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. Other parameters might be affected as well.

PUBLISHED
Vendor
Campcodes
Product
Computer Sales and Inventory System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9793

A vulnerability was detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /setting/admin.php of the component Setting Handler. Performing manipulation of the argument ddlBranch results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Apartment Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9792

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /e_dashboard/e_all_info.php. Such manipulation of the argument mid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Apartment Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9791

A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fromAdvSetMacMtuWan. This manipulation of the argument wanMTU causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Tenda
Product
AC20
Provider severity
HIGH
Conflicts
2

CVE-2025-9790

A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the file /admin/updateabout.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
SourceCodester
Product
Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9789

A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file /admin/edituser.php. The manipulation of the argument userid leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9788

A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_class.php. Executing manipulation of the argument id_no can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
SourceCodester, Campcodes
Product
School Log Management System, School Log Management System
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2025-9787

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Applications Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9786

A vulnerability was found in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /teacher_signup.php. Performing manipulation of the argument firstname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Other parameters might be affected as well.

PUBLISHED
Vendor
Campcodes
Product
Online Learning Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9785

PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to use a self-signed certificate. If the customer does not fully configure the system to leverage the trust database on the clients, it opens up the communication between clients and the server to man-in-the-middle attacks.  It was discovered that certain parts o

PUBLISHED
Vendor
PaperCut
Product
Print Deploy
Provider severity
HIGH
Conflicts
0

CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Enterprise Linux 10, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat build of Apache Camel 4.14.2 for Spring Boot 3.5.8, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat Single Sign-On 7, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.0, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat build of Apache Camel - HawtIO 4, Red Hat JBoss Enterprise Application Platform 7.4, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
Provider severity
HIGH
Conflicts
2

CVE-2025-9783

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
TOTOLINK
Product
A702R
Provider severity
HIGH
Conflicts
2

CVE-2025-9782

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton. Performing manipulation of the argument submit-url results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
TOTOLINK
Product
A702R
Provider severity
HIGH
Conflicts
2

CVE-2025-9781

A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such manipulation of the argument ip6addr leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
A702R
Provider severity
HIGH
Conflicts
2

CVE-2025-9780

A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This manipulation of the argument mac causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
A702R
Provider severity
HIGH
Conflicts
2

CVE-2025-9779

A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
A702R
Provider severity
HIGH
Conflicts
2

CVE-2025-9778

A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
Tenda
Product
W12
Provider severity
LOW
Conflicts
2

CVE-2025-9776

The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in all versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract

PUBLISHED
Vendor
catfolders
Product
CatFolders – WordPress Media Library Folders & Categories
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9775

A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the argument image results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
n/a
Product
RemoteClinic
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9774

A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patients/edit-patient.php. The manipulation of the argument Email leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
RemoteClinic
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9773

A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Executing manipulation of the argument Last Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
n/a
Product
RemoteClinic
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9772

A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argument image results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
n/a
Product
RemoteClinic
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9771

A security vulnerability has been detected in SourceCodester Eye Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file /main/search_index_Diagnosis.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Eye Clinic Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9770

A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Dashboard Login. This manipulation of the argument Password causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Campcodes
Product
Hospital Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9769

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
D-Link
Product
DI-7400G+
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9768

A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the file /Admin/mode.php. The manipulation of the argument code leads to sql injection. The attack is possible to be carried out remotely.

PUBLISHED
Vendor
itsourcecode
Product
Sports Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9767

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /Admin/sporttype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
itsourcecode
Product
Sports Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9766

A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
Sports Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9765

A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournament_details.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Sports Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9764

A flaw has been found in itsourcecode Sports Management System 1.0. Impacted is an unknown function of the file /Admin/resultdetails.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Sports Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9763

A vulnerability was detected in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /student_signup.php. The manipulation of the argument Username results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Learning Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9762

The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function in all versions up to, and including, 1.0.4b. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
westi
Product
Post By Email
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9761

A security vulnerability has been detected in Campcodes Online Feeds Product Inventory System 1.0. This vulnerability affects unknown code of the file /feeds/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Feeds Product Inventory System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9760

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9759

A security flaw has been discovered in Campcodes/SourceCodester Courier Management System 1.0. Affected by this issue is the function Signup of the file /ajax.php. Performing manipulation of the argument lastname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
SourceCodester, Campcodes
Product
Courier Management System, Courier Management System
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2025-9758

A vulnerability was identified in deepakmisal24 Chemical Inventory Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory_form.php. Such manipulation of the argument chem_name leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

PUBLISHED
Vendor
deepakmisal24
Product
Chemical Inventory Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9757

A vulnerability was determined in Campcodes/SourceCodester Courier Management System 1.0. Affected is the function Login of the file /ajax.php. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
SourceCodester, Campcodes
Product
Courier Management System, Courier Management System
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2025-9756

A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
PHPGurukul
Product
User Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9755

A vulnerability has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of the argument msg leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

PUBLISHED
Vendor
Khanakag-17
Product
Library Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9754

A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Hospital Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9753

A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Hospital Management System
Provider severity
LOW, MEDIUM
Conflicts
2