Total
3248 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-10123 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-09-24 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | |||||
CVE-2025-10634 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-09-24 | 6.5 MEDIUM | 6.3 MEDIUM |
A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. | |||||
CVE-2025-10814 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-09-24 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |||||
CVE-2025-10401 | 1 Dlink | 2 Dir-823x, Dir-823x Firmware | 2025-09-24 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |||||
CVE-2025-10781 | 1 Campcodes | 1 Online Learning Management System | 2025-09-23 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was identified in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_class.php. Such manipulation of the argument class_name leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |||||
CVE-2025-10782 | 1 Campcodes | 1 Online Learning Management System | 2025-09-23 | 7.5 HIGH | 7.3 HIGH |
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/class.php. Performing manipulation of the argument class_name results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. | |||||
CVE-2025-10783 | 1 Campcodes | 1 Online Learning Management System | 2025-09-23 | 7.5 HIGH | 7.3 HIGH |
A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_subject.php. Executing manipulation of the argument subject_code can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be exploited. | |||||
CVE-2025-10784 | 1 Campcodes | 1 Online Learning Management System | 2025-09-23 | 7.5 HIGH | 7.3 HIGH |
A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_subject.php. The manipulation of the argument subject_code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |||||
CVE-2025-10812 | 1 Angeljudesuarez | 1 Hostel Management System | 2025-09-23 | 7.5 HIGH | 7.3 HIGH |
A vulnerability has been found in code-projects Hostel Management System 1.0. This impacts an unknown function of the file /justines/admin/mod_amenities/index.php?view=view. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-10813 | 1 Angeljudesuarez | 1 Hostel Management System | 2025-09-23 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was found in code-projects Hostel Management System 1.0. Affected is an unknown function of the file /justines/admin/mod_reports/index.php. The manipulation of the argument Home results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |||||
CVE-2025-10762 | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM | ||
A vulnerability was found in kuaifan DooTask up to 1.2.49. Affected by this vulnerability is an unknown functionality of the file app/Http/Controllers/Api/UsersController.php. The manipulation of the argument keys[department] results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |||||
CVE-2025-10628 | 1 Dlink | 2 Dir-852, Dir-852 Firmware | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
CVE-2025-10629 | 1 Dlink | 2 Dir-852, Dir-852 Firmware | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery Protocol Service. Executing manipulation of the argument ST can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
CVE-2025-10483 | 1 Janobe | 1 Online Student File Management System | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM |
A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Other parameters might be affected as well. | |||||
CVE-2025-10482 | 1 Janobe | 1 Online Student File Management System | 2025-09-22 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |||||
CVE-2025-10481 | 1 Janobe | 1 Online Student File Management System | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM |
A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | |||||
CVE-2025-1691 | 1 Mongodb | 1 Mongosh | 2025-09-22 | N/A | 7.6 HIGH |
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input and run obfuscated malicious text. This requires user interaction in the form of the user using ‘tab’ to autocomplete text that is a prefix of the attacker’s prepared autocompletion. This issue affects mongosh versions prior to 2.3.9. The vulnerability is exploitable only when mongosh is connected to a cluster that is partially or fully controlled by an attacker. | |||||
CVE-2025-10602 | 1 Janobe | 1 Online Exam Form Submission | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s1.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |||||
CVE-2025-10563 | 1 Campcodes | 1 Grocery Sales And Inventory System | 2025-09-22 | 7.5 HIGH | 7.3 HIGH |
A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_category. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-10592 | 1 Carenlove | 1 Online Public Access Catalog | 2025-09-22 | 6.5 MEDIUM | 6.3 MEDIUM |
A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |