Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-9752

A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-852
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9751

A weakness has been identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /login.php. This manipulation of the argument Username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Campcodes
Product
Online Learning Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9750

A security flaw has been discovered in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
Campcodes
Product
Online Learning Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9749

A vulnerability was identified in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b. This affects an unknown part of the file /src/update.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

PUBLISHED
Vendor
HKritesh009
Product
Grocery List Management Web App
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9748

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing manipulation of the argument ipsecno can lead to stack-based buffer overflow. The attack may be performed from remote.

PUBLISHED
Vendor
Tenda
Product
CH22
Provider severity
HIGH
Conflicts
2

CVE-2025-9747

A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.0 is able to address this issue. The name of the patch is 9ab8562d3f1e953da93fed63f9ee802c7ea26a9a. It is suggested to upgrade the affected component. The vendor expla

PUBLISHED
Vendor
n/a
Product
Koillection
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9746

A vulnerability was detected in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Hospital Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9745

A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
D-Link
Product
DI-500WF
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9744

A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Campcodes
Product
Online Loan Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9743

A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. Impacted is an unknown function of the file login_attendance2.php. Performing manipulation of the argument employee_id/date results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
code-projects
Product
Human Resource Integrated System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9742

A vulnerability was identified in code-projects Human Resource Integrated System 1.0. This issue affects some unknown processing of the file /login.php. Such manipulation of the argument user/pass leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
code-projects
Product
Human Resource Integrated System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9741

A vulnerability was determined in code-projects Human Resource Integrated System 1.0. This vulnerability affects unknown code of the file /login_query12.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
code-projects
Product
Human Resource Integrated System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9740

A vulnerability was found in code-projects Human Resource Integrated System 1.0. This affects an unknown part of the file /log_query.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Human Resource Integrated System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9739

A vulnerability has been found in Campcodes Online Water Billing System 1.0. Affected by this issue is some unknown functionality of the file /process.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Water Billing System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9738

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9737

A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/queryName results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new ver

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9736

A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9735

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in th

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9734

A security flaw has been discovered in O2OA up to 10.0-410. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/applicationName results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be f

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9733

A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. This impacts an unknown function of the file /login_timeee.php. Performing manipulation of the argument emp_id results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
code-projects
Product
Human Resource Integrated System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9732

A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dcmtk/dcmimage/diybrpxt.h of the component dcm2img. Such manipulation leads to memory corruption. Local access is required to approach this attack. The name of the patch is 7ad81d69b. It is best practice to apply a patch to resolve this issue.

PUBLISHED
Vendor
n/a
Product
DCMTK
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9731

A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
AC9
Provider severity
LOW
Conflicts
2

CVE-2025-9730

A vulnerability was found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /ajax/updateProfile.php. The manipulation of the argument user_id results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
Apartment Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9729

A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Online Course Registration
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9728

A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password leads to cross site scripting. The attack can be executed remotely. The name of the patch is bbd4c42c66ab818142240348173a669d1d2537fe. Applying a patch is advised to resolve this issue.

PUBLISHED
Vendor
givanz
Product
Vvveb
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9727

A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulation of the argument service causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-816L
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9726

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /review.php. The manipulation of the argument pid results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
Campcodes
Product
Farm Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9725

A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interface. The manipulation leads to use of hard-coded password. The attack must be carried out locally. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit is publicly available and might be used. Upgrading to version 2.3.13 is able to address this issue. It is recommended to upgrade the affected comp

PUBLISHED
Vendor
Cudy
Product
LT500E
Provider severity
LOW
Conflicts
2

CVE-2025-9724

A vulnerability was determined in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /intranet/educar_nivel_ensino_cad.php. Executing manipulation of the argument nm_nivel/descricao can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9723

A vulnerability was found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_regime_cad.php. Performing manipulation of the argument nm_tipo results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9722

A vulnerability has been found in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_tipo_ocorrencia_disciplinar_cad.php. Such manipulation of the argument nm_tipo/descricao leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9721

A flaw has been found in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module/FormulaMedia/edit. This manipulation of the argument nome/formulaMedia causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9720

A vulnerability was detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/TabelaArredondamento/edit of the component Cadastrar tabela de arredondamento Page. The manipulation of the argument Nome results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9719

A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_processplatform_assemble_designer/jaxrs/script of the component Personal Profile Page. Executing manipulation of the argument name/alias/description/applicationName can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9718

A security flaw has been discovered in O2OA up to 10.0-410. This affects an unknown part of the file /x_processplatform_assemble_designer/jaxrs/process of the component Personal Profile Page. Performing manipulation of the argument name/alias results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the n

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9717

A vulnerability was identified in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_organization_assemble_control/jaxrs/unit/ of the component Personal Profile Page. Such manipulation of the argument name/shortName/distinguishedName/pinyin/pinyinInitial/levelName leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9716

A vulnerability was determined in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_processplatform_assemble_designer/jaxrs/form of the component Personal Profile Page. This manipulation of the argument name/alias/description causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixe

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9715

A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_cms_assemble_control/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9714

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero before making potentially recursive calls. When such functions were called recursively this could allow for uncontrolled recursion and lead to a stack overflow. These functions now preserve recursion depth

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, libxml2, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1510, libxml2, RUGGEDCOM ROX RX5000, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX MX5000, RUGGEDCOM ROX RX1500
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9713

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

PUBLISHED
Vendor
Ivanti
Product
Endpoint Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-9712

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

PUBLISHED
Vendor
Ivanti
Product
Endpoint Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-9711

A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.

PUBLISHED
Vendor
Brocade
Product
Fabric OS
Provider severity
HIGH
Conflicts
0

CVE-2025-9710

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.

PUBLISHED
Vendor
Unknown
Product
Responsive Lightbox & Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9709

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of modification to the hardware system possible.

PUBLISHED
Vendor
Nordic Semiconductor
Product
nRF52810
Provider severity
HIGH
Conflicts
1

CVE-2025-9708

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate communication with the Kubernetes API server, leading to possible man-in-the-middle attacks and API impersonation.

PUBLISHED
Vendor
Kubernetes
Product
Kubernetes CSharp Client
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9706

A security vulnerability has been detected in SourceCodester Water Billing System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Water Billing System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9705

A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
SourceCodester
Product
Water Billing System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9704

A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
SourceCodester
Product
Water Billing System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9703

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

PUBLISHED
Vendor
Unknown
Product
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9702

A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /sales_report.php. The manipulation of the argument month leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
SourceCodester
Product
Simple Cafe Billing System
Provider severity
HIGH, MEDIUM
Conflicts
2