CVE tracker
367 subscribers
5.02K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-4865 - iSourcecode Restaurant Management System SQL Injection

CVE ID : CVE-2025-4865
Published : May 18, 2025, 8:15 a.m. | 1 hour, 9 minutes ago
Description : A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4866 - Weibocom Rill-Flow Management Console Code Injection Vulnerability

CVE ID : CVE-2025-4866
Published : May 18, 2025, 8:15 a.m. | 1 hour, 9 minutes ago
Description : A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Management Console. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4867 - Tenda A15 Denial of Service Vulnerability

CVE ID : CVE-2025-4867
Published : May 18, 2025, 9:15 a.m. | 4 hours, 9 minutes ago
Description : A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as problematic. Affected by this vulnerability is the function formArpNerworkSet of the file /goform/ArpNerworkSet. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4868 - Merikbest Ecommerce-Spring-Reactjs Path Traversal Vulnerability

CVE ID : CVE-2025-4868
Published : May 18, 2025, 9:15 a.m. | 4 hours, 9 minutes ago
Description : A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v1/admin/ of the component File Upload Endpoint. The manipulation of the argument filename leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4869 - iSourcecode Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4869
Published : May 18, 2025, 10:15 a.m. | 3 hours, 9 minutes ago
Description : A vulnerability classified as critical has been found in itsourcecode Restaurant Management System 1.0. This affects an unknown part of the file /admin/member_update.php. The manipulation of the argument menu leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4870 - iSourcecode Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4870
Published : May 18, 2025, 10:15 a.m. | 3 hours, 9 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4871 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-4871
Published : May 18, 2025, 11:15 a.m. | 2 hours, 9 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component REST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4872 - FreeFloat FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-4872
Published : May 18, 2025, 11:15 a.m. | 2 hours, 9 minutes ago
Description : A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component CCC Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4873 - PHPGurukul News Portal SQL Injection Vulnerability

CVE ID : CVE-2025-4873
Published : May 18, 2025, 12:15 p.m. | 1 hour, 9 minutes ago
Description : A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4874 - "PHPGurukul News Portal Project SQL Injection Vulnerability"

CVE ID : CVE-2025-4874
Published : May 18, 2025, 12:15 p.m. | 1 hour, 9 minutes ago
Description : A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4875 - Campcodes Online Shopping Portal SQL Injection Vulnerability

CVE ID : CVE-2025-4875
Published : May 18, 2025, 1:15 p.m. | 4 hours, 10 minutes ago
Description : A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4880 - PHPGurukul News Portal SQL Injection Vulnerability

CVE ID : CVE-2025-4880
Published : May 18, 2025, 1:15 p.m. | 4 hours, 10 minutes ago
Description : A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4881 - iSourcecode Restaurant Management System SQL Injection

CVE ID : CVE-2025-4881
Published : May 18, 2025, 2:15 p.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user_save.php. The manipulation of the argument username/name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4882 - iSourcecode Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4882
Published : May 18, 2025, 2:15 p.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_update.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48219 - O2 UK IMS E-UTRAN Cell Identity Leak

CVE ID : CVE-2025-48219
Published : May 18, 2025, 3:15 p.m. | 2 hours, 10 minutes ago
Description : O2 UK through 2025-05-17 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gpp field of a Cellular-Network-Info SIP header, aka an ECI (E-UTRAN Cell Identity) leak. The Cell ID might be usable to identify a cell location via crowdsourced data, and might correspond to a small physical area (e.g., if the called party is in a city centre). Removal of the Cellular-Network-Info header is mentioned in section 4.4.19 of ETSI TS 124 229.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4883 - D-Link DI-8100 ASP Context Buffer Overflow

CVE ID : CVE-2025-4883
Published : May 18, 2025, 3:15 p.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been declared as critical. This vulnerability affects the function ctxz_asp of the file /ctxz.asp of the component Connection Limit Page. The manipulation of the argument def/defTcp/defUdp/defIcmp/defOther leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4884 - iSourcecode Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4884
Published : May 18, 2025, 3:15 p.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/assign_save.php. The manipulation of the argument team leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4885 - iSourcecode Sales and Inventory System SQL Injection Vulnerability

CVE ID : CVE-2025-4885
Published : May 18, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as critical has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument serial leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4886 - iSourcecode Sales and Inventory System SQL Injection Vulnerability

CVE ID : CVE-2025-4886
Published : May 18, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/product_update.php. The manipulation of the argument serial leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4887 - SourceCodester Online Student Clearance System Cross-Site Request Forgery Vulnerability

CVE ID : CVE-2025-4887
Published : May 18, 2025, 5:15 p.m. | 4 hours, 10 minutes ago
Description : A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4888 - Code-projects Pharmacy Management System Buffer Overflow Vulnerability

CVE ID : CVE-2025-4888
Published : May 18, 2025, 5:15 p.m. | 4 hours, 10 minutes ago
Description : A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. This affects the function medicineType::take_order of the component Add Order Details. The manipulation leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...