Latest CVE Feed
- 
                                
                                9.8CRITICALCVE-2025-11077A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remot... Read more Affected Products : online_learning_management_system- Published: Sep. 27, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11469A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /pages/save_customer.php. Executing manipulation of the argument Contact can lead to sql injection. The attack ... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-10587The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exi... Read more Affected Products : community_events- Published: Oct. 08, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11475A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing manipulation of the argument user_id can lead to sql injection. The attack... Read more Affected Products : advanced_library_management_system- Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11506A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the argument searchdata results in sql injection. It is poss... Read more Affected Products : beauty_parlour_management_system- Published: Oct. 08, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-34196Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password... Read more - Published: Sep. 29, 2025
- Modified: Oct. 16, 2025
- Vuln Type: Cryptography
 
- 
                                
                                9.8CRITICALCVE-2025-11401A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /pages/save_curr.php. This manipulation of the argument currcode causes sql injection. The attack is possible to be carried out remo... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 07, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11287A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConnectionfunction of the file src/services/sseService.ts. Such manipulation leads to improper authentication. The attack may be launched re... Read more Affected Products : mcphub- Published: Oct. 05, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Authentication
 
- 
                                
                                9.8CRITICALCVE-2025-11342A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument coursecode can lead to sql injection. The attack can be executed re... Read more Affected Products : online_course_registration_site- Published: Oct. 06, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-10586The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis... Read more Affected Products : community_events- Published: Oct. 09, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11348A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be lau... Read more Affected Products : online_apartment_visitor_management_system- Published: Oct. 07, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-34212Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls an unverified third-party image, downloads the VirtualBox Exte... Read more - Published: Sep. 29, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Supply Chain
 
- 
                                
                                9.8CRITICALCVE-2025-61622Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted ... Read more Affected Products : fory- Published: Oct. 01, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-54592FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if... Read more Affected Products : freshrss- Published: Sep. 29, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Authentication
 
- 
                                
                                9.8CRITICALCVE-2025-61455SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authenticatio... Read more Affected Products :- Published: Oct. 20, 2025
- Modified: Oct. 21, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11040A vulnerability was detected in code-projects Hostel Management System 1.0. Affected by this issue is some unknown functionality of the file /justines/admin/mod_users/index.php?view=view. The manipulation of the argument ID results in sql injection. The a... Read more - Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11420A vulnerability was detected in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/edit_order_details.php. The manipulation of the argument order_id results in sql injection. The attack may be launched remotely. The e... Read more - Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11046A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can b... Read more Affected Products : weknora- Published: Sep. 26, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                9.8CRITICALCVE-2025-11039A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_edit1.php. The manipulation of the argument ID leads to sql injection. Remote... Read more Affected Products : computer_sales_and_inventory_system- Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-59681An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted d... Read more Affected Products : django- Published: Oct. 01, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
 
                         
                         
                         
                                             
                                            