38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-1743
Pichome Web ⚡ nuclei
6.9
MEDIUM
EPSS
9.1%
2025 CWE-22 0 PoCs

A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13002
Bookstore Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2024 CWE-89 2 PoCs

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /order_process.php. The manipulation of the argument fnm leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2021-41174
grafana DevOps Web ⚡ nuclei
6.9
MEDIUM
EPSS
87.7%
2021 CWE-79 0 PoCs

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }}

CVE-2025-0533
Campaign Management System Platform for Women Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8185
ABC Courier Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /getbyid.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-6323
Pre-School Enrollment System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /enrollment.php. The manipulation of the argument fathername leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2025-13561
Company Website CMS Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVE-2025-4714
Sales and Inventory System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/reprint.php. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8469
Online Hotel Reservation System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8471
Online Admission System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument a_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-34442
AVideo Web
6.9
MEDIUM
EPSS
47.5%
2025 CWE-497 1 PoC

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.

CVE-2025-1963
Online Hotel Booking Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7542
User Registration & Login and User Management System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2015-20117
RealtyScript Web
6.9
MEDIUM
EPSS
0.1%
2015 CWE-352 2 PoCs

Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to register new users with arbitrary credentials and escalate privileges to SUPERUSER level.

CVE-2015-20113
RealtyScript Web
6.9
MEDIUM
EPSS
0.0%
2015 CWE-352 2 PoCs

Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malicious scripts. Attackers can craft malicious web pages that execute unauthorized actions when logged-in users visit them, or inject persistent scripts that execute in the application context.

CVE-2025-8953
COVID 19 Testing Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-9509
Apartment Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/fair_info_all.php. Performing manipulation of the argument fid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

CVE-2025-5840
Client Database Management System Web
6.9
MEDIUM
EPSS
0.3%
2025 CWE-434 2 PoCs

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to initiate the attack remotely.

CVE-2025-1596
Best Church Management Software Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 2 PoCs

A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-66573
Solstice Pod API Session Key Extraction via API Endpoint Web
6.9
MEDIUM
EPSS
0.1%
2025 CWE-319 1 PoC

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.