Common Vulnerabilities and Exposures (CVE)

CVE-2025-32095

Dec 25, 2025 04:48:35 UTC

Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.

CVE-2025-32096

Dec 25, 2025 04:46:04 UTC

Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVE-2025-15077

Dec 25, 2025 04:02:08 UTC

A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /form137.php. The manipulation of the argument ID leads to sql injection. The attack may be in...

CVE-2025-15076

Dec 25, 2025 03:32:06 UTC

A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the p...

CVE-2025-15075

Dec 25, 2025 03:02:06 UTC

A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /student_p.php. Performing manipulation of the argument ID results in sql injection. The attack can be...

CVE-2025-15074

Dec 25, 2025 02:32:06 UTC

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to sql injection. It is possible to launch the attack...

CVE-2025-68922

Dec 24, 2025 23:12:22 UTC

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

CVE-2025-15073

Dec 24, 2025 23:02:07 UTC

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the at...

CVE-2025-68920

Dec 24, 2025 22:43:13 UTC

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

CVE-2024-39037

Dec 24, 2025 21:48:23 UTC

MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu parameter.

CVE-2024-40317

Dec 24, 2025 21:47:08 UTC

A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter HTTP.

CVE-2025-68919

Dec 24, 2025 21:29:13 UTC

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to pot...

CVE-2025-68917

Dec 24, 2025 20:38:16 UTC

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

CVE-2025-8769

Dec 24, 2025 20:36:42 UTC

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code...

CVE-2018-25127

Dec 24, 2025 20:27:27 UTC

SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that submit forged requ...