5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-1596
Best Church Management Software Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 2 PoCs

A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-66573
Solstice Pod API Session Key Extraction via API Endpoint Web
6.9
MEDIUM
EPSS
0.1%
2025 CWE-319 1 PoC

Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.

CVE-2025-8953
COVID 19 Testing Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1963
Online Hotel Booking Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-34442
AVideo Web
6.9
MEDIUM
EPSS
47.5%
2025 CWE-497 1 PoC

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.

CVE-2025-15002
SeaCMS Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8185
ABC Courier Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /getbyid.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-12325
Best Salon Management System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-10600
Online Exam Form Submission Web
6.9
MEDIUM
EPSS
0.1%
2025 CWE-434 1 PoC

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulation of the argument img causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used.

CVE-2025-4331
Online Student Clearance System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 2 PoCs

A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation of the argument id/username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8926
COVID 19 Testing Management System Web Database
6.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-6323
Pre-School Enrollment System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /enrollment.php. The manipulation of the argument fathername leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2025-2322
springboot-openai-chatgpt Web Networking
6.9
MEDIUM
EPSS
0.1%
2025 CWE-798 1 PoC

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the file /chatgpt-boot/src/main/java/org/springblade/modules/mjkj/controller/OpenController.java. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any wa

CVE-2025-13578
Library System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11615
Best Salon Management System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add_invoice.php. Performing manipulation of the argument ServiceId results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

CVE-2025-9842
Parking Management System 停车场管理系统 General
6.9
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used.

CVE-2025-10078
Online Polling System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

CVE-2025-4935
Stock Management System Web Database
6.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-34336
eGovFramework/egovframe-common-components General
6.9
MEDIUM
EPSS
0.7%
2025 CWE-434 2 PoCs

eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a shared upload helper, and store the file on the server under a framework-controlled path. The framework then returns a download URL that can be used to retrieve the uploaded content, including an attacker-controlled Content-Type within the limits of the image upload functionality. Whi

CVE-2025-10789
Online Hotel Reservation System Web Database
6.9
MEDIUM
EPSS
0.0%
2025 CWE-89 2 PoCs

A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file deleteslide.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.