5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-58583
Enterprise Analytics General
5.3
MEDIUM
EPSS
0.1%
2025 CWE-497 1 PoC

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

CVE-2025-10594
Online Student File Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. Executing manipulation of the argument stud_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

CVE-2025-13564
Pre-School Management System Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-404 1 PoC

A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

CVE-2025-56435
Software Genérico Web Database
5.3
MEDIUM
EPSS
0.2%
2025 1 PoC

SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id.

CVE-2025-12810
Secret Server On-Prem General
5.3
MEDIUM
EPSS
0.0%
2025 CWE-287 2 PoCs

Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue affects Secret Server On-Prem: 11.8.1, 11.9.6, 11.9.25. A secret with "change password on check in" enabled automatically checks in even when the password change fails after reaching its retry limit. This leaves the secret in an inconsistent state with the wrong password. Remediation: Upgrade to 11.9.47 or later. The secret will remain checked out when the password change fails.

CVE-2025-13345
Train Station Ticketing System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-27451
Endress+Hauser MEAC300-FNADE4 General
5.3
MEDIUM
EPSS
0.4%
2025 CWE-204 1 PoC

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVE-2025-8163
deer-wms-2 Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/role/list. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-11478
Farm Management System Web Database
5.3
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

A weakness has been identified in SourceCodester Farm Management System 1.0. This issue affects some unknown processing of the file /myCart.php. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

CVE-2025-1831
zz Database
5.3
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is the function GetDBUser of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-10410
Link Status Checker Web
5.3
MEDIUM
EPSS
0.1%
2025 CWE-918 1 PoC

A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument proxy leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2025-3964
Books-Management-System Web
5.3
MEDIUM
EPSS
0.2%
2025 CWE-352 1 PoC

A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an unknown function of the file /api/article/del of the component Article Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-47184
Software Genérico Web
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message.

CVE-2025-20989
Samsung Mobile Devices General
5.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.

CVE-2025-53013
himmelblau Cloud
5.2
MEDIUM
EPSS
0.1%
2025 CWE-287 2 PoCs

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate to a Linux host via Himmelblau using an *invalid* Linux Hello PIN, provided the host is offline. While the user gains access to the local system, Single Sign-On (SSO) fails due to the network being down and the inability to issue tokens (due to a failure to unlock the Hello key). The core issue lies in an incorrect assumption within the `acquire_token_by_hello_for_business_key` function: it was expected to return a `TPMFail` er

CVE-2025-21047
Samsung Mobile Devices Web
5.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

CVE-2025-20987
Samsung Mobile Devices General
5.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.

CVE-2025-46707
Graphics DDK General
5.2
MEDIUM
EPSS
0.1%
2025 CWE-668 1 PoC

Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

CVE-2025-5381
CMS Web
5.1
MEDIUM
EPSS
1.3%
2025 CWE-22 1 PoC

A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of the component Admin Panel. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-2377
Vehicle Management System Web
5.1
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /confirmbooking.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting product names.