A vulnerability classified as critical was found in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket Handler. The manipulation results in creation of temporary file with insecure permissions.
This vulnerability is reported as CVE-2025-9474. The attack requires a local approach. Moreover, an exploit is present.
A critical vulnerability in Docker Desktop for Windows and macOS allows compromising the host by running a malicious container, even if the Enhanced Container Isolation (ECI) protection is active. [...]
A vulnerability classified as critical has been found in SourceCodester Online Bank Management System 1.0. This impacts an unknown function of the file /feedback.php. The manipulation of the argument msg leads to sql injection.
This vulnerability is documented as CVE-2025-9473. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability described as critical has been identified in Vibes Plugin up to 2.2.0 on WordPress. This affects an unknown function. Executing manipulation of the argument resource can lead to sql injection.
This vulnerability is registered as CVE-2025-9172. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in Rebuild 3.7.7. The impacted element is the function prehandle of the file /commons/ip-location of the component GET Request Handler. Performing manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2024-46412. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as critical has been found in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file about-us.php. Such manipulation of the argument pagetitle leads to sql injection.
This vulnerability is listed as CVE-2025-56216. The attack may be performed from a remote location. There is no available exploit.
A vulnerability identified as critical has been detected in Hitron CGNF-TWN up to 3.1.1.43-TWN-pre3. Impacted is an unknown function of the component Telnet Service. This manipulation causes command injection.
This vulnerability is tracked as CVE-2025-44179. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /owner_utility/add_owner_utility.php. The manipulation of the argument ID results in sql injection.
This vulnerability is identified as CVE-2025-9472. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability was found in itsourcecode Apartment Management System 1.0. It has been rated as critical. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is referenced as CVE-2025-9471. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability was found in itsourcecode Apartment Management System 1.0. It has been declared as critical. This affects an unknown part of the file /management/add_m_committee.php. Executing manipulation of the argument ID can lead to sql injection.
The identification of this vulnerability is CVE-2025-9470. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in itsourcecode Apartment Management System 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file /fund/add_fund.php. Performing manipulation of the argument ID results in sql injection.
This vulnerability was named CVE-2025-9469. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in itsourcecode Apartment Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /bill/add_bill.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-9468. The attack can be launched remotely. Moreover, an exploit is present.