🚨 CVE-2025-2655
A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Other parameters might be affected as well.
🎖@cveNotify
A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Other parameters might be affected as well.
🎖@cveNotify
GitHub
cve/AC Repair and Services System using/SQL-8.md at main · Colorado-all/cve
Contribute to Colorado-all/cve development by creating an account on GitHub.
❤1
🚨 CVE-2025-54236
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
🎖@cveNotify
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security Updates Available for Adobe Commerce | APSB25-88
🚨 CVE-2025-13544
A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/travel-File Upload.docx at main · www223-ai/CVE
cve. Contribute to www223-ai/CVE development by creating an account on GitHub.
🚨 CVE-2025-13545
A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/travel-sql.docx at main · www223-ai/CVE
cve. Contribute to www223-ai/CVE development by creating an account on GitHub.
🚨 CVE-2025-13546
A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
🎖@cveNotify
A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
🎖@cveNotify
GitHub
CVE/travel-sql2.docx at main · www223-ai/CVE
cve. Contribute to www223-ai/CVE development by creating an account on GitHub.
🚨 CVE-2025-13547
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
🎖@cveNotify
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
🎖@cveNotify
GitHub
D-Link DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formDdns · Issue #30 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formDdns Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Product D-lin...
🚨 CVE-2025-31216
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.
🎖@cveNotify
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.
🎖@cveNotify
Apple Support
About the security content of iOS 18.5 and iPadOS 18.5 - Apple Support
This document describes the security content of iOS 18.5 and iPadOS 18.5.
🚨 CVE-2025-31248
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.5, macOS Sonoma 14.7.3. An app may be able to access sensitive user data.
🎖@cveNotify
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.5, macOS Sonoma 14.7.3. An app may be able to access sensitive user data.
🎖@cveNotify
Apple Support
About the security content of macOS Sonoma 14.7.3 - Apple Support
This document describes the security content of macOS Sonoma 14.7.3.
❤1
🚨 CVE-2025-31266
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
🎖@cveNotify
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
🎖@cveNotify
Apple Support
About the security content of macOS Sequoia 15.5 - Apple Support
This document describes the security content of macOS Sequoia 15.5.
🚨 CVE-2025-43374
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Sequoia 15.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory.
🎖@cveNotify
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, visionOS 2.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Sequoia 15.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory.
🎖@cveNotify
Apple Support
About the security content of macOS Sonoma 14.7.3 - Apple Support
This document describes the security content of macOS Sonoma 14.7.3.
🚨 CVE-2025-13548
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
🎖@cveNotify
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
🎖@cveNotify
GitHub
D-Link DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formFirewallAdv · Issue #31 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formFirewallAdv Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Produc...
🚨 CVE-2025-13549
A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
🎖@cveNotify
A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
🎖@cveNotify
GitHub
D-Link DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formNtp · Issue #32 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formNtp Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Product D-link...
🚨 CVE-2025-13550
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
🎖@cveNotify
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
🎖@cveNotify
GitHub
D-Link DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formVpnConfigSetup · Issue #33 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formVpnConfigSetup Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Pro...
🚨 CVE-2025-13551
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
🎖@cveNotify
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
🎖@cveNotify
GitHub
D-Link DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formWanConfigSetup · Issue #35 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formWanConfigSetup Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Pro...
🔥1
🚨 CVE-2025-13552
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
🎖@cveNotify
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
🎖@cveNotify
GitHub
D-Link DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formWlEncrypt · Issue #36 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DIR-822k TK_1.00_20250513164613 - Buffer Overflow in /boafrm/formWlEncrypt Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Product ...
🚨 CVE-2025-13553
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
🎖@cveNotify
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
🎖@cveNotify
GitHub
D-Link DWR-M920 B2 V1.1.50 - Buffer Overflow in /boafrm/formPinManageSetup · Issue #45 · QIU-DIE/CVE
NAME OF AFFECTED PRODUCT(S) D-link Router DWR-M920 B2 V1.1.50 - Buffer Overflow in /boafrm/formPinManageSetup Vulnerability Details Detail Information Vendor D-Link (友讯电子设备(上海)有限公司) Product D-link ...
🚨 CVE-2025-13554
A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
🎖@cveNotify
A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
🎖@cveNotify
GitHub
Campcodes Supplier Management System V1.0 /Supply_Management_System/index.php SQL injection · Issue #3 · arpcyber060/CVE
Campcodes Supplier Management System V1.0 /Supply_Management_System/index.php SQL injection NAME OF AFFECTED PRODUCT(S) Supplier Management System Vendor Homepage https://www.campcodes.com/projects...
🚨 CVE-2025-13555
A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
🎖@cveNotify
A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
🎖@cveNotify
GitHub
Campcodes School File Management System V1.0 /School%20File%20Management%20System/ SQL injection · Issue #4 · arpcyber070/CVE
Campcodes School File Management System V1.0 /School%20File%20Management%20System/ SQL injection NAME OF AFFECTED PRODUCT(S) School File Management System Vendor Homepage https://www.campcodes.com/...
🚨 CVE-2025-13556
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
🎖@cveNotify
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
🎖@cveNotify
GitHub
# Campcodes Online Polling System V1.0 /Online_Polling_System/admin/checklogin.php SQL injection · Issue #2 · ProgramShowMaker/CVE
Campcodes Online Polling System V1.0 /Online_Polling_System/admin/checklogin.php SQL injection NAME OF AFFECTED PRODUCT(S) Online Polling System Vendor Homepage https://www.campcodes.com/projects/p...
🚨 CVE-2024-21922
A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
🎖@cveNotify
A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
🎖@cveNotify
AMD
AMD StoreMi™ Vulnerabilities
🚨 CVE-2024-21923
Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
🎖@cveNotify
Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
🎖@cveNotify
AMD
AMD StoreMi™ Vulnerabilities