CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2025-58169

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE.

    Published: 27 Aug 2025
    Unknown

    CVE-2025-58170

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE.

    Published: 27 Aug 2025
    Unknown

    CVE-2025-58171

    Last Modified: 4 Sept 2025

    This CVE is a duplicate of another CVE.

    Published: 27 Aug 2025
    Unknown

    CVE-2025-58166

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE.

    Published: 27 Aug 2025
    Unknown

    CVE-2025-58167

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE.

    Published: 27 Aug 2025
    Unknown

    CVE-2025-58164

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE, CVE-2025-58163.

    Published: 27 Aug 2025
    Unknown

    CVE-2025-58165

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE, CVE-2025-58163.

    Published: 27 Aug 2025
    2.1
    Low

    CVE-2025-9531

    Last Modified: 15 Sept 2026

    A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 2.12 mitigates this issue. It is suggested to upgrade the affected component. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced."

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9529

    Last Modified: 3 Sept 2025

    A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include of the file /index.php. This manipulation of the argument page causes file inclusion. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

    Published: 27 Aug 2025
    2
    Low

    CVE-2025-9528

    Last Modified: 9 Oct 2025

    A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Aug 2025
    7.4
    High

    CVE-2025-9527

    Last Modified: 9 Oct 2025

    A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of the argument ack_policy results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Aug 2025
    7.4
    High

    CVE-2025-9526

    Last Modified: 9 Oct 2025

    A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Aug 2025
    7.4
    High

    CVE-2025-9525

    Last Modified: 9 Oct 2025

    A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulation of the argument DeviceName/lanIp causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Aug 2025
    8.9
    High

    CVE-2025-9523

    Last Modified: 20 Sept 2025

    A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

    Published: 27 Aug 2025
    8.8
    High

    CVE-2025-30064

    Last Modified: 15 Apr 2026

    An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user.

    Published: 27 Aug 2025
    9.4
    Critical

    CVE-2025-30063

    Last Modified: 15 Apr 2026

    The configuration file containing database logins and passwords is readable by any local user.

    Published: 27 Aug 2025
    6.9
    Medium

    CVE-2025-30061

    Last Modified: 15 Apr 2026

    In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parameter.

    Published: 27 Aug 2025
    6.9
    Medium

    CVE-2025-30060

    Last Modified: 15 Apr 2026

    In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" parameter.

    Published: 27 Aug 2025
    6.9
    Medium

    CVE-2025-30059

    Last Modified: 15 Apr 2026

    In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.

    Published: 27 Aug 2025
    6.9
    Medium

    CVE-2025-30058

    Last Modified: 15 Apr 2026

    In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.

    Published: 27 Aug 2025
    9.4
    Critical

    CVE-2025-30057

    Last Modified: 15 Apr 2026

    In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.

    Published: 27 Aug 2025
    9.4
    Critical

    CVE-2025-30056

    Last Modified: 15 Apr 2026

    The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system.

    Published: 27 Aug 2025
    9
    Critical

    CVE-2025-30055

    Last Modified: 15 Apr 2026

    The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.

    Published: 27 Aug 2025
    5.3
    Medium

    CVE-2025-30048

    Last Modified: 15 Apr 2026

    The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authentication.

    Published: 27 Aug 2025
    9
    Critical

    CVE-2025-30041

    Last Modified: 15 Apr 2026

    The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" expose data containing session IDs.

    Published: 27 Aug 2025
    9
    Critical

    CVE-2025-30040

    Last Modified: 15 Apr 2026

    The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/userlogxls.pl" endpoint.

    Published: 27 Aug 2025
    9
    Critical

    CVE-2025-30039

    Last Modified: 15 Apr 2026

    Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges.

    Published: 27 Aug 2025
    7.3
    High

    CVE-2025-30038

    Last Modified: 15 Apr 2026

    The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.

    Published: 27 Aug 2025
    8.8
    High

    CVE-2025-30037

    Last Modified: 15 Apr 2026

    The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publicly accessible without authentication to any host able to reach the application server on port 443/tcp.

    Published: 27 Aug 2025
    8.8
    High

    CVE-2025-30036

    Last Modified: 15 Apr 2026

    Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.

    Published: 27 Aug 2025
    9.4
    Critical

    CVE-2025-2313

    Last Modified: 15 Apr 2026

    In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.

    Published: 27 Aug 2025
    6.5
    Medium

    CVE-2021-4459

    Last Modified: 15 Apr 2026

    An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.

    Published: 27 Aug 2025
    6.3
    Medium

    CVE-2025-9514

    Last Modified: 26 Nov 2025

    A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.

    Published: 27 Aug 2025
    8.5
    High

    CVE-2025-57797

    Last Modified: 15 Apr 2026

    Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vulnerability is exploited, an authenticated local attacker may escalate privileges and execute an arbitrary command.

    Published: 27 Aug 2025
    6.3
    Medium

    CVE-2025-9513

    Last Modified: 15 Apr 2026

    A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the file src/net/penetrate/handshake/mod.rs. This manipulation of the argument priv_key causes inadequate encryption strength. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is reported as difficult.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9511

    Last Modified: 2 Sept 2025

    A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /visitor/addvisitor.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 27 Aug 2025
    8.5
    High

    CVE-2025-57846

    Last Modified: 15 Apr 2026

    Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacker may replace a service executable on the system where the product is running, potentially allowing arbitrary code execution with SYSTEM privileges.

    Published: 27 Aug 2025
    5.3
    Medium

    CVE-2025-48081

    Last Modified: 28 Apr 2026

    Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects Printeers Print & Ship: from n/a through 1.17.0.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9510

    Last Modified: 2 Sept 2025

    A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /branch/addbranch.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9509

    Last Modified: 2 Sept 2025

    A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/fair_info_all.php. Performing manipulation of the argument fid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9508

    Last Modified: 2 Sept 2025

    A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /report/rented_info.php. The manipulation of the argument rsid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9507

    Last Modified: 2 Sept 2025

    A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/visitor_info.php. Executing manipulation of the argument vid can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9506

    Last Modified: 2 Sept 2025

    A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_plan. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit has been disclosed to the public and may be used.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9505

    Last Modified: 2 Sept 2025

    A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_loan_type. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9504

    Last Modified: 2 Sept 2025

    A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

    Published: 27 Aug 2025
    5.9
    Medium

    CVE-2025-49035

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups admin-menu-groups allows Stored XSS.This issue affects Admin Menu Groups: from n/a through <= 0.1.2.

    Published: 27 Aug 2025
    5.9
    Medium

    CVE-2025-49039

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View link-view allows Stored XSS.This issue affects Link View: from n/a through <= 0.8.0.

    Published: 27 Aug 2025
    4.3
    Medium

    CVE-2025-49040

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9503

    Last Modified: 2 Sept 2025

    A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown function of the file /ajax.php?action=save_borrower. The manipulation of the argument lastname leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

    Published: 27 Aug 2025
    5.5
    Medium

    CVE-2025-9502

    Last Modified: 2 Sept 2025

    A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the file /ajax.php?action=save_payment. Executing manipulation of the argument loan_id can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

    Published: 27 Aug 2025