Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-7214

A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow of the component MD5. The manipulation leads to risky cryptographic algorithm. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
FNKvision
Product
FNK-GU2
Provider severity
LOW
Conflicts
2

CVE-2025-7213

A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and test interface with improper access control. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
FNKvision
Product
FNK-GU2
Provider severity
MEDIUM
Conflicts
1

CVE-2025-7212

A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insertAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Insurance Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7211

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
LifeStyle Store
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7210

A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/profile_update.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects, Fabian Ros
Product
Library Management System, Library Management System
Provider severity
MEDIUM
Conflicts
3

CVE-2025-7209

A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerability is the function value_decode in the library src/libsec/port/x509.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releas

PUBLISHED
Vendor
9fans
Product
plan9port
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7208

A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is b3e0655

PUBLISHED
Vendor
9fans
Product
plan9port
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7207

A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 1fdd96104180cc0fb5d3cb086b05ab6458911bb9. It is recommended to apply a patch to fix this issue.

PUBLISHED
Vendor
n/a
Product
mruby
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7206

A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file switch_language.cgi of the component httpd. The manipulation of the argument Language leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-825
Provider severity
CRITICAL
Conflicts
2

CVE-2025-7205

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with GiveWP worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Additionally, they need to trick an administrator

PUBLISHED
Vendor
stellarwp
Product
GiveWP – Donation Plugin and Fundraising Platform
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7204

In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found to return an overly verbose user object, which included encrypted password hashes for other users. Authenticated users could then retrieve these hashes.  An attacker or privileged user could then use these exposed hashes to conduct offline brute-force or dictionary attacks. Such attacks could lead to credential compro

PUBLISHED
Vendor
ConnectWise
Product
PSA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7202

A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.

PUBLISHED
Vendor
Elgato, Elgato, Elgato, Elgato, Elgato, Elgato, Elgato
Product
Ring Light, Key Light Neo, Light Strip, Key Light Air, Key Light, Light Strip Pro, Key Light Mini
Provider severity
MEDIUM
Conflicts
1

CVE-2025-7200

A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file quantity_upd.php. The manipulation of the argument med_name/med_cat/ex_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details

PUBLISHED
Vendor
krishna9772
Product
Pharmacy Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7199

A vulnerability, which was classified as critical, has been found in code-projects Library System 1.0. This issue affects some unknown processing of the file /notapprove.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7198

A vulnerability classified as critical was found in code-projects Jonnys Liquor 1.0. This vulnerability affects unknown code of the file /admin/admin-area.php. The manipulation of the argument drink leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Jonnys Liquor
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7197

A vulnerability classified as critical has been found in code-projects Jonnys Liquor 1.0. This affects an unknown part of the file /admin/delete-row.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Jonnys Liquor
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7196

A vulnerability was found in code-projects Jonnys Liquor 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /browse.php. The manipulation of the argument Search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Jonnys Liquor
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7195

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, operator-framework, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat build of Apicurio Registry 3, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.15, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Openshift Data Foundation 4.15, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Openshift Data Foundation 4.14, multicluster engine for Kubernetes 2.7, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.15, multicluster engine for Kubernetes 2.7, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.16, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.16, multicluster engine for Kubernetes 2.6, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.15, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.14, Red Hat Advanced Cluster Management for Kubernetes 2.12, Multicluster Engine for Kubernetes, RHEL-9-CNV-4.20, Multicluster Global Hub, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.17, multicluster engine for Kubernetes 2.7, multicluster engine for Kubernetes 2.7, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Openshift Data Foundation 4.15, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Web Terminal, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.7, multicluster engine for Kubernetes 2.8, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.6, multicluster engine for Kubernetes 2.9, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.17, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.12, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.18, multicluster engine for Kubernetes 2.7, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.6, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Openshift Data Foundation 4.14, Red Hat Advanced Cluster Management for Kubernetes 2, RHEL-9-CNV-4.17, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.16, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.15, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Openshift Data Foundation 4.15, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.7, Red Hat Openshift Data Foundation 4.14, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.6, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.14, Multicluster Engine for Kubernetes, multicluster engine for Kubernetes 2.6, Red Hat Openshift Data Foundation 4.17, multicluster engine for Kubernetes 2.6, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.17, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.6, multicluster engine for Kubernetes 2.7, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.15, multicluster engine for Kubernetes 2.7, Red Hat Openshift Data Foundation 4.15, multicluster engine for Kubernetes 2.7, multicluster engine for Kubernetes 2.7, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Openshift Data Foundation 4.17, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Advanced Cluster Management for Kubernetes 2.12, Compliance Operator 1, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Openshift Data Foundation 4.17, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.15, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Openshift Data Foundation 4.15, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.18, multicluster engine for Kubernetes 2.9, Multicluster Global Hub, Red Hat Openshift Data Foundation 4.15, Red Hat Openshift Data Foundation 4.18, RHEL-9-CNV-4.18, multicluster engine for Kubernetes 2.7, multicluster engine for Kubernetes 2.9, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.15, Compliance Operator 1, Red Hat Openshift Data Foundation 4.15, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Openshift Data Foundation 4.17, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift Virtualization 4, multicluster engine for Kubernetes 2.7, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Openshift Data Foundation 4.15, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.15, Red Hat Web Terminal, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.14, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.14, Red Hat Openshift Data Foundation 4.18, File Integrity Operator 1, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.17, operator-sdk, multicluster engine for Kubernetes 2.9, Red Hat Openshift Data Foundation 4.14, multicluster engine for Kubernetes 2.9, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.17, Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Engine for Kubernetes, multicluster engine for Kubernetes 2.7, Red Hat build of Apicurio Registry 2, multicluster engine for Kubernetes 2.8, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Advanced Cluster Management for Kubernetes 2.14, multicluster engine for Kubernetes 2.9, Red Hat Openshift Data Foundation 4.17, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.17, Red Hat Openshift Data Foundation 4.17, multicluster engine for Kubernetes 2.9, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.15, Red Hat Fuse 7, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.7, multicluster engine for Kubernetes 2.9, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.14, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.14, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.7, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.15
Provider severity
MEDIUM
Conflicts
1

CVE-2025-7194

A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file ip_position.asp of the component jhttpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
D-Link
Product
DI-500WF
Provider severity
HIGH
Conflicts
2

CVE-2025-7193

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/suppliercontroller.php. The manipulation of the argument supplier leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Agri-Trading Online Shopping System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7192

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-645
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7191

A vulnerability has been found in code-projects Student Enrollment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Student Enrollment System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7190

A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7189

A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Chat System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7188

A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Chat System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7187

A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Chat System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7186

A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Chat System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7185

A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /approve.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7184

A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. This affects an unknown part of the file /user/teacher/books.php. The manipulation of the argument Search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7183

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/customer_account.php. The manipulation of the argument Customer leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Sales and Inventory System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7182

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/modules/subject/edit.php. The manipulation of the argument pre leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Student Transcript Processing System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7181

A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /test.php. The manipulation of the argument uploadedfile leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Staff Audit System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7180

A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Staff Audit System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7179

A vulnerability classified as critical was found in code-projects Library System 1.0. This vulnerability affects unknown code of the file /add-teacher.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7178

A vulnerability classified as critical has been found in code-projects Food Distributor Site 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Food Distributor Site
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7177

A vulnerability was found in PHPGurukul Car Washing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/editcar-washpoint.php. The manipulation of the argument wpid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Car Washing Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7176

A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view-medhistory.php. The manipulation of the argument viewid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Hospital Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7175

A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
E-Commerce Site
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7174

A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file /teacher-issue-book.php. The manipulation of the argument idn leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7173

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-student.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7172

A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects an unknown part of the file /headlogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Crime Reporting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7171

A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of the file /policelogin.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Crime Reporting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7170

A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Crime Reporting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7169

A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation of the argument location leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Crime Reporting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7168

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /userlogin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Crime Reporting System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7167

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Responsive Blog Site
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7166

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Responsive Blog Site
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7165

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul, Campcodes
Product
Cyber Cafe Management System, Cyber Cafe Management System
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2025-7164

A vulnerability has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul, Campcodes
Product
Cyber Cafe Management System, Cyber Cafe Management System
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2025-7163

A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/add-animals.php. The manipulation of the argument cnum leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Zoo Management System
Provider severity
MEDIUM
Conflicts
2