Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-9701

A vulnerability was determined in SourceCodester Simple Cafe Billing System 1.0. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
SourceCodester
Product
Simple Cafe Billing System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9700

A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Book Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9699

A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed from a remote location. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Polling System Code
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9698

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.

PUBLISHED
Vendor
Unknown
Product
The Plus Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9697

The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PUBLISHED
Vendor
Unknown
Product
Ajax WooSearch
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9696

The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform actions such as firmware replacement, disabling power production, modifying grid settings, creating SSH tunnels, altering firewall settings, and manipulating connected devices.

PUBLISHED
Vendor
SunPower
Product
PVS6
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9695

A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components. The attack can only be performed from a local environment. The exploit is publicly available and might be used.

PUBLISHED
Vendor
GalleryVault
Product
Gallery Vault App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9694

A vulnerability was determined in Campcodes Advanced Online Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Campcodes
Product
Advanced Online Voting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9693

The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the postInsertUserProcess function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PUBLISHED
Vendor
khaledsaikat
Product
User Meta – User Profile Builder and User management plugin
Provider severity
HIGH
Conflicts
0

CVE-2025-9692

A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Campcodes
Product
Online Shopping System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9691

A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Shopping System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9690

A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the file /index.php/stock/vendordetails. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Advanced School Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9689

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/stock/item_select. The manipulation of the argument q results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Advanced School Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9688

A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used. The identifier of the patch is 3984137fc0c44110f1ef876adb008885b05a6e18. To fix this issue

PUBLISHED
Vendor
n/a
Product
Mupen64Plus
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9687

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoApi. Executing manipulation can lead to improper authorization. The attack may be performed from a remote location. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9686

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component Listagem de áreas de conhecimento Page. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9685

A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas de conhecimento Page. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9684

A vulnerability was determined in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/edit of the component Formula de Cálculo de Média Page. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9683

A vulnerability was found in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /x_cms_assemble_control/jaxrs/form of the component Personal Profile Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9682

A vulnerability has been found in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the component Personal Profile Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9681

A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9680

A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9679

A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Student Information System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9678

A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
Campcodes
Product
Online Loan Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9677

A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.duige.hzw.multilingual. The manipulation results in improper export of android application components. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Modo
Product
Legend of the Phoenix
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9676

A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
NCSOFT
Product
Universe App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9675

A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. Executing manipulation can lead to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
n/a
Product
Voice Changer App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9674

A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Transbyte
Product
Scooper News App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9673

A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android application components. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Kakao
Product
헤이카카오 Hey Kakao App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9672

A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. The manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
Rejseplanen App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9671

A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.passport.cash. Executing manipulation can lead to improper export of android application components. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
UAB
Product
Paytend App
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9670

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
mixmark-io
Product
turndown
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9669

A vulnerability has been found in Jinher OA 1.0. This issue affects some unknown processing of the file GetTreeDate.aspx. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Jinher
Product
OA
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9667

A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delete_account.php of the component Admin Panel. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Grading System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9666

A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some unknown functionality of the file /delete_student.php of the component Admin Panel. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Grading System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9665

A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_student.php of the component Admin Panel. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
code-projects
Product
Simple Grading System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9664

A security flaw has been discovered in code-projects Simple Grading System 1.0. Affected is an unknown function of the file /add_student_grade.php of the component Admin Panel. The manipulation of the argument Add results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
code-projects
Product
Simple Grading System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9663

A vulnerability was identified in code-projects Simple Grading System 1.0. This impacts an unknown function of the file /edit_account.php of the component Admin Panel. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
code-projects
Product
Simple Grading System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9662

A vulnerability was determined in code-projects Simple Grading System 1.0. This affects an unknown function of the file /login.php of the component Admin Panel. Executing manipulation can lead to sql injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
code-projects
Product
Simple Grading System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9661

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

PUBLISHED
Vendor
Hitachi, Hitachi, Hitachi, Hitachi
Product
Hitachi Virtual Storage Platform One Block 23, Hitachi Virtual Storage Platform One Block 28, Hitachi Virtual Storage Platform One Block 26, Hitachi Virtual Storage Platform One Block 24
Provider severity
HIGH
Conflicts
1

CVE-2025-9660

A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
SourceCodester
Product
Bakeshop Online Ordering System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9659

A vulnerability has been found in O2OA up to 10.0-410. The affected element is an unknown function of the file /x_portal_assemble_designer/jaxrs/widget of the component Personal Profile Page. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9658

A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/jaxrs/dict/ of the component Personal Profile Page. This manipulation of the argument name/alias/description causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9657

A vulnerability was detected in O2OA up to 10.0-410. This issue affects some unknown processing of the file /x_program_center/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9656

A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Directory Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9655

A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble_control/jaxrs/person/ of the component Personal Profile Page. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be launched remotely. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."

PUBLISHED
Vendor
n/a
Product
O2OA
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9654

A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing manipulation results in command injection. The attack can be initiated remotely. Upgrading to version 1.0.4 and 1.1.0 can resolve this issue. The patch is named cd2566a948b696501abfa6c6b03462cac5fb43d8. It is advisable to upgrade the affected component.

PUBLISHED
Vendor
AiondaDotCom
Product
mcp-ssh
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9653

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_projeto_cad.php of the component Cadastrar projeto Page. Such manipulation of the argument nome/observacao leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9652

A vulnerability was determined in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /intranet/educar_transferencia_tipo_cad.php of the component Cadastrar tipo de transferência Page. This manipulation of the argument nm_tipo/desc_tipo causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Portabilis
Product
i-Educar
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9651

A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown function of the file /chat.php. The manipulation of the argument user_id results in sql injection. The attack may be performed from a remote location. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

PUBLISHED
Vendor
shafhasan
Product
chatbox
Provider severity
MEDIUM
Conflicts
2