Total
18759 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-63719 | 1 Campcodes | 1 Online Hospital Management System | 2025-11-24 | 7.3 High |
| Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username. | ||||
| CVE-2025-13420 | 2 Angeljudesuarez, Itsourcecode | 2 Human Resource Management System, Human Resource Management System | 2025-11-24 | 7.3 High |
| A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argument eventSubject causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. | ||||
| CVE-2025-13422 | 2 Darkseid, Freeprojectscodes | 2 Sports Club Management System, Sports Club Management System | 2025-11-24 | 7.3 High |
| A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown function of the file /dashboard/admin/change_s_pwd.php. Performing manipulation of the argument login_id results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. | ||||
| CVE-2025-13123 | 1 Amttgroup | 2 Hibos, Hotel Broadband Operation System | 2025-11-24 | 6.3 Medium |
| A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2025-13421 | 2 Angeljudesuarez, Itsourcecode | 2 Human Resource Management System, Human Resource Management System | 2025-11-24 | 7.3 High |
| A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argument noticeDesc leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2025-2655 | 1 Oretnom23 | 1 Ac Repair And Services System | 2025-11-22 | 7.3 High |
| A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Other parameters might be affected as well. | ||||
| CVE-2025-13449 | 1 Oretnom23 | 1 Online Shop Project | 2025-11-21 | 7.3 High |
| A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | ||||
| CVE-2025-13451 | 1 Oretnom23 | 1 Online Shop Project | 2025-11-21 | 7.3 High |
| A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | ||||
| CVE-2025-63512 | 1 Kishan0725 | 1 Hospital Management System | 2025-11-20 | 6.5 Medium |
| kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into a dynamic SQL query. | ||||
| CVE-2025-13251 | 2 Datax-web Project, Weiye-jing | 2 Datax-web, Datax-web | 2025-11-20 | 6.3 Medium |
| A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | ||||
| CVE-2025-13267 | 3 Dental Clinic Appointment Reservation System Project, Jkev, Sourcecodester | 3 Dental Clinic Appointment Reservation System, Dental Clinic Appointment Reservation System, Dental Clinic Appointment Reservation System | 2025-11-20 | 6.3 Medium |
| A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. | ||||
| CVE-2025-63694 | 1 Dzzoffice | 1 Dzzoffice | 2025-11-20 | 9.8 Critical |
| DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage. | ||||
| CVE-2025-65022 | 1 Portabilis | 1 I-educar | 2025-11-20 | 7.2 High |
| i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_agenda request parameter, which is directly concatenated into multiple SQL queries without proper sanitization. This issue has been patched in commit b473f92. | ||||
| CVE-2025-65023 | 1 Portabilis | 1 I-educar | 2025-11-20 | 7.2 High |
| i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_funcionario_vinculo GET parameter, which is directly concatenated into an SQL query without proper sanitization. This issue has been patched in commit a00dfa3. | ||||
| CVE-2025-13396 | 1 Carmelogarcia | 1 Courier Management System | 2025-11-20 | 6.3 Medium |
| A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | ||||
| CVE-2025-65093 | 1 Librenms | 1 Librenms | 2025-11-20 | 5.5 Medium |
| LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parameter is interpolated directly into an SQL query without proper sanitization or parameter binding, allowing an attacker to manipulate the query logic and infer data from the database through conditional responses. This issue has been patched in version 25.11.0. | ||||
| CVE-2025-13346 | 1 Oretnom23 | 1 Train Station Ticketing System | 2025-11-19 | 6.3 Medium |
| A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_station. Performing manipulation of the argument id/station results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. | ||||
| CVE-2025-13347 | 2 Oretnom23, Sourcecodester | 2 Train Station Ticketing System, Train Station Ticketing System | 2025-11-19 | 6.3 Medium |
| A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | ||||
| CVE-2025-64084 | 2 Cloudlog, Magicbug | 2 Cloudlog, Cloudlog | 2025-11-19 | 5.4 Medium |
| An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. This allows a remote, authenticated attacker to execute arbitrary SQL commands by injecting a malicious payload, which is then concatenated directly into a raw SQL query in the vucc_qso_details function. | ||||
| CVE-2025-44034 | 1 Aaluoxiang | 1 Oa System | 2025-11-19 | 8.0 High |
| SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController | ||||