5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-13564
Pre-School Management System Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-404 1 PoC

A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

CVE-2025-13345
Train Station Ticketing System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-10410
Link Status Checker Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-918 1 PoC

A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument proxy leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-10605
i-Educar Web
5.3
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

CVE-2025-6879
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.3%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add-tax.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1168
Contact Manager with Export to VCF Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php. The manipulation of the argument contact leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-8772
NukeViet Web
5.3
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file /admin/index.php?language=en&nv=upload of the component Module Handler. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-54766
XorMon-NG Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-648 2 PoCs

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to export the appliance configuration, exposing sensitive information.

CVE-2025-1278
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2025 CWE-1220 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVE-2025-6581
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-customer.php. The manipulation of the argument name/email/mobilenum/gender/details/dob/marriage_date leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11047
i-Educar Web
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 2 PoCs

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVE-2025-53965
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container lacks bounds checking, which can cause a fatal error.

CVE-2025-1576
Real Estate Property Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax_state.php. The manipulation of the argument StateName as part of String leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-46078
Software Genérico Web
5.3
MEDIUM
EPSS
0.3%
2025 2 PoCs

HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server

CVE-2025-1745
pb-cms Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-352 1 PoC

A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-13264
Online Magazine Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 2 PoCs

A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited.

CVE-2025-10822
platform General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the file /sys/smslog/queryAll. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVE-2025-10483
Online Student File Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. This manipulation of the argument firstname causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Other parameters might be affected as well.

CVE-2025-11346
ILIAS General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-502 1 PoC

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version 8.24, 9.14 and 10.2 is able to mitigate this issue. It is advisable to upgrade the affected component.

CVE-2025-8829
RE6250 General
5.3
MEDIUM
EPSS
0.8%
2025 CWE-78 1 PoC

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.