5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-10954
github.com/nyaruka/phonenumbers General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-1286 1 PoC

Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".

CVE-2025-8934
Sales Management System Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation of the argument select2112 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-6608
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-services.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-10820
platform General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /topic/queryAll. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is now public and may be used.

CVE-2025-2126
JUX Real Estate Web Database
5.3
MEDIUM
EPSS
1.2%
2025 CWE-89 1 PoC

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component GET Parameter Handler. The manipulation of the argument title leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-8368
i-Educar Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code of the file /intranet/pesquisa_pessoa_lst.php. The manipulation of the argument campo_busca/cpf leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-10408
Student Grading System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A security flaw has been discovered in SourceCodester Student Grading System 1.0. Affected by this issue is some unknown functionality of the file /edit_user.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

CVE-2025-24582
12 Step Meeting List General ⚡ nuclei
5.3
MEDIUM
EPSS
6.4%
2025 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.16.5.

CVE-2025-58585
Baggage Analytics General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-497 1 PoC

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

CVE-2025-12931
Food Ordering System Web Networking Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVE-2025-10625
Online Exam Form Submission Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A vulnerability was detected in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /user/dashboard.php?page=update_profile. The manipulation of the argument phone results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. Other parameters might be affected as well.

CVE-2025-9607
i-Educar Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of the component Tabelas de Arredondamento Page. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVE-2025-3118
Online Tutor Portal Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7746
ATV630/650/660/680/6A0/6B0/6L0 Altivar Process Drives Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read data in a victim’s browser.

CVE-2025-12696
HelloLeads CRM Form Shortcode Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them

CVE-2025-8366
i-Educar Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /intranet/educar_servidor_lst.php. The manipulation of the argument nome/matricula_servidor leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-6605
Best Salon Management System Web Database
5.3
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability affects unknown code of the file /panel/edit-staff.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-9196
Trinity Audio – Text to Speech AI audio player to convert content into audio Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.5%
2025 CWE-200 1 PoC

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

CVE-2025-8999
Sydney Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions up to, and including, 2.56. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate various theme modules.

CVE-2025-4545
Content Management System Web
5.3
MEDIUM
EPSS
0.5%
2025 CWE-22 1 PoC

A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.php of the component File Handler. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.