CVE-2025-11663 - Campcodes Online Beauty Parlor Management System manage-services.php sql injection
CVE ID : CVE-2025-11663
Published : Oct. 13, 2025, 6:15 a.m. | 3 hours, 18 minutes ago
Description : A weakness has been identified in Campcodes Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/manage-services.php. This manipulation of the argument sername causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11663
Published : Oct. 13, 2025, 6:15 a.m. | 3 hours, 18 minutes ago
Description : A weakness has been identified in Campcodes Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/manage-services.php. This manipulation of the argument sername causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9698 - The Plus Addons for Elementor < 6.3.16 - Author+ Stored XSS
CVE ID : CVE-2025-9698
Published : Oct. 13, 2025, 6:15 a.m. | 3 hours, 18 minutes ago
Description : The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9698
Published : Oct. 13, 2025, 6:15 a.m. | 3 hours, 18 minutes ago
Description : The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author to perform Stored Cross-Site Scripting attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0636 - Arbitrary Code Execution vulnerability in Ericsson RAN Compute and Site Controller
CVE ID : CVE-2025-0636
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-0636
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11664 - Campcodes Online Beauty Parlor Management System search-appointment.php sql injection
CVE ID : CVE-2025-11664
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11664
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11665 - D-Link DAP-2695 Firmware Update rgbin fwupdater_main os command injection
CVE ID : CVE-2025-11665
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The attack may be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11665
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The attack may be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11666 - Tenda RP3 Pro Firmware Update force_upgrade.sh hard-coded password
CVE ID : CVE-2025-11666
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11666
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27258 - Ericsson Network Manager: escalation of privilege vulnerability
CVE ID : CVE-2025-27258
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-27258
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27259 - Ericsson Network Manager: improper neutralization of user controlled input
CVE ID : CVE-2025-27259
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.
Severity: 2.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-27259
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.
Severity: 2.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8915 - Hardcoded TLS private key in Kiloview N30 firmware
CVE ID : CVE-2025-8915
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the network
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-8915
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the network
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9265 - API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
CVE ID : CVE-2025-9265
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9265
Published : Oct. 13, 2025, 7:15 a.m. | 2 hours, 18 minutes ago
Description : A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10552 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x
CVE ID : CVE-2025-10552
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-10552
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10556 - Stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x
CVE ID : CVE-2025-10556
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-10556
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10557 - Stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x
CVE ID : CVE-2025-10557
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-10557
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10558 - Stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x
CVE ID : CVE-2025-10558
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-10558
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11667 - code-projects Automated Voting System add_candidate_modal.php. sql injection
CVE ID : CVE-2025-11667
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11667
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11668 - code-projects Automated Voting System update_user.php sql injection
CVE ID : CVE-2025-11668
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of the argument Password causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11668
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of the argument Password causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11671 - EBM Technologies|Uniweb/SoliPACS WebServer - Missing Authentication
CVE ID : CVE-2025-11671
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as account names and IP addresses.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11671
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as account names and IP addresses.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11672 - EBM Technologies|Uniweb/SoliPACS WebServer - Missing Authentication
CVE ID : CVE-2025-11672
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11672
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11673 - PiExtract |SOOP-CLM - Hidden Functionality
CVE ID : CVE-2025-11673
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11673
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploit a hidden functionality to execute arbitrary code on the server.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11674 - PiExtract|SOOP-CLM - Server-Side Request Forgery
CVE ID : CVE-2025-11674
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11674
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11675 - Ragic|Enterprise Cloud Database - Arbitrary File Upload
CVE ID : CVE-2025-11675
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11675
Published : Oct. 13, 2025, 8:15 a.m. | 1 hour, 18 minutes ago
Description : Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...