Vulnerabilities (CVE)

Filtered by CWE-74
Angry Yack Logo
Total 4091 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-15143 1 Eyoucms 1 Eyoucms 2026-02-24 5.8 MEDIUM 4.7 MEDIUM
A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/FilemanagerLogic.php of the component Backend Template Management. The manipulation of the argument content results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-15088 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.loadPostils of the file /je/postil/postil/loadPostil. Performing a manipulation of the argument keyWord results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-15048 1 Tenda 2 Wh450, Wh450 Firmware 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-13811 1 Jsnjfz 1 Webstack-guns 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/common/constant/factory/PageFactory.java. Executing a manipulation of the argument sort can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-13792 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Upgrading to version 8.20.105 and 8.24.98 addresses this issue. Upgrading the affected component is advised.
CVE-2025-13556 1 Campcodes 1 Online Polling System 2026-02-24 7.5 HIGH 7.3 HIGH
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
CVE-2025-13555 1 Campcodes 1 School File Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
CVE-2025-13299 1 Itsourcecode 1 Web-based Internet Laboratory Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
CVE-2025-13298 1 Itsourcecode 1 Web-based Internet Laboratory Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVE-2025-13291 1 Campcodes 1 Supplier Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
CVE-2025-13280 1 Codeastro 1 Simple Inventory System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-13274 1 Campcodes 1 School Fees Payment Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_fees. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2025-13273 1 Campcodes 1 School Fees Payment Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_payment. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-13260 1 Campcodes 1 Supplier Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument cmbProductUnit leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13259 1 Campcodes 1 Supplier Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
CVE-2025-13256 1 Projectworlds 1 Advanced Library Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of the argument roll_number can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2025-13255 1 Projectworlds 1 Advanced Library Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a manipulation of the argument book_pub/book_title results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-13247 1 Phpgurukul 1 Tourism Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-13172 1 Codeastro 1 Gym Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-13170 1 Fabian 1 Simple Online Hotel Reservation System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of the argument admin_id results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVE-2025-12617 1 Angeljudesuarez 1 Billing System 2026-02-24 7.5 HIGH 7.3 HIGH
A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument Password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2025-12612 1 Campcodes 1 School Fees Payment Management System 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-12610 1 Codeastro 1 Gym Management System 2026-02-24 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-12609 1 Codeastro 1 Gym Management System 2026-02-24 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation of the argument id/ini_weight results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
CVE-2025-12594 1 Fabian 1 Simple Online Hotel Reservation System 2026-02-24 5.8 MEDIUM 4.7 MEDIUM
A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation of the argument Name results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
CVE-2025-11507 1 Phpgurukul 1 Beauty Parlour Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2025-11506 1 Phpgurukul 1 Beauty Parlour Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the argument searchdata results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-11503 1 Phpgurukul 1 Beauty Parlour Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11475 1 Projectworlds 1 Advanced Library Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing a manipulation of the argument user_id can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11434 1 Fabian 1 Student Transcript Processing System 2026-02-24 7.5 HIGH 7.3 HIGH
A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2025-11416 1 Phpgurukul 1 Beauty Parlour Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/invoices.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-11350 1 Campcodes 1 Online Apartment Visitor Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. The affected element is an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-11348 1 Campcodes 1 Online Apartment Visitor Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11334 1 Campcodes 1 Online Apartment Visitor Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-detail.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVE-2025-11303 1 Belkin 2 F9k1015, F9k1015 Firmware 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-11298 1 Belkin 2 F9k1015, F9k1015 Firmware 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWanStatic. Executing a manipulation of the argument m_wan_ipaddr can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-11292 1 Belkin 2 F9k1015, F9k1015 Firmware 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing a manipulation of the argument wan_ipaddr can lead to command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-11288 1 Crmeb 1 Crmeb 2026-02-24 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-15003 1 Seacms 1 Seacms 2026-02-24 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php. Performing a manipulation of the argument e_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVE-2025-14990 1 Campcodes 1 Complete Online Beauty Parlor Management System 2026-02-24 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing a manipulation of the argument viewid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.