VulDB Updates Updates
- CVE-2025-13577 | PHPGurukul Hostel Management System 2.1 /register-complaint.php cdetails cross site scripting (EUVD-2025-198597 / CNNVD-202511-2684)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability classified as problematic was found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing manipulation of the argument cdetails can lead to cross site scripting. This vulnerability is registered as CVE-2025-13577. It is possible to launch the attack remotely. Furthermore, an exploit is available.
- CVE-2025-13576 | code-projects Blog Site 1.0 /admin.php improper authorization (EUVD-2025-198595 / CNNVD-202511-2685)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability classified as critical has been found in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper authorization. This vulnerability is cataloged as CVE-2025-13576. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. Multiple endpoints are affected.
- CVE-2025-13580 | code-projects Library System 1.0 /mail.php ID sql injection (EUVD-2025-198598)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability has been found in code-projects Library System 1.0 and classified as critical. Affected is an unknown function of the file /mail.php. This manipulation of the argument ID causes sql injection. This vulnerability appears as CVE-2025-13580. The attack may be initiated remotely. In addition, an exploit is available.
- CVE-2025-58305 | Huawei HarmonyOS 5.0.1 Gallery app improper authentication (EUVD-2025-199858)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability was found in Huawei HarmonyOS 5.0.1 and classified as critical. This issue affects some unknown processing of the component Gallery app. Such manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2025-58305. Local access is required to approach this attack. No exploit exists. It is suggested to upgrade the affected component.
- CVE-2025-13583 | code-projects Question Paper Generator 1.0 POST Parameter /signupscript.php Fname sql injectionby vuldb.com on December 2, 2025 at 5:58 am
A vulnerability was found in code-projects Question Paper Generator 1.0. It has been declared as critical. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulation of the argument Fname can lead to sql injection. This vulnerability is handled as CVE-2025-13583. The attack can be executed remotely. Additionally, an exploit exists.
- CVE-2025-13582 | code-projects Jonnys Liquor 1.0 GET Parameter /detail.php Product sql injectionby vuldb.com on December 2, 2025 at 5:58 am
A vulnerability was found in code-projects Jonnys Liquor 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file /detail.php of the component GET Parameter Handler. Performing manipulation of the argument Product results in sql injection. This vulnerability is known as CVE-2025-13582. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
- CVE-2025-13586 | SourceCodester Online Student Clearance System 1.0 changepassword.php txtconfirm_password sql injectionby vuldb.com on December 2, 2025 at 5:58 am
A vulnerability identified as critical has been detected in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. This manipulation of the argument txtconfirm_password causes sql injection. The identification of this vulnerability is CVE-2025-13586. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2025-58302 | Huawei HarmonyOS/EMUI Settings access control (EUVD-2025-199860)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability, which was classified as critical, was found in Huawei HarmonyOS and EMUI. This affects an unknown part of the component Settings Module. The manipulation results in improper access controls. This vulnerability is known as CVE-2025-58302. Attacking locally is a requirement. No exploit is available. You should upgrade the affected component.
- CVE-2025-58304 | Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 File Management information management (EUVD-2025-199859)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability has been found in Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 and classified as problematic. This vulnerability affects unknown code of the component File Management Module. This manipulation causes information management error. This vulnerability is handled as CVE-2025-58304. It is feasible to perform the attack on the physical device. There is not any exploit available. The affected component should be upgraded.
- CVE-2025-13575 | code-projects Blog Site 1.0 Category blog.php category_exists name/field sql injection (EUVD-2025-198596 / CNNVD-202511-2686)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability described as critical has been identified in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql injection. This vulnerability is listed as CVE-2025-13575. The attack may be performed from remote. In addition, an exploit is available. Multiple endpoints are affected.
- CVE-2025-13579 | code-projects Library System 1.0 /return.php ID sql injection (EUVD-2025-198599 / CNNVD-202511-2683)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability, which was classified as critical, was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argument ID results in sql injection. This vulnerability is reported as CVE-2025-13579. The attack can be launched remotely. Moreover, an exploit is present.
- CVE-2025-58308 | Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 Call security check (EUVD-2025-199857)by vuldb.com on December 2, 2025 at 5:58 am
A vulnerability was found in Huawei HarmonyOS 5.0.1/5.1.0/6.0.0. It has been classified as problematic. Impacted is an unknown function of the component Call Module. Performing manipulation results in security check for standard. This vulnerability was named CVE-2025-58308. The attack needs to be approached locally. There is no available exploit. Upgrading the affected component is recommended.
- CVE-2023-53190 | Linux Kernel up to 6.0.18/6.1.4 vxlan_vnigroup_init memory leak (EUVD-2023-59786)by vuldb.com on December 2, 2025 at 5:50 am
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.0.18/6.1.4. Affected is the function vxlan_vnigroup_init. The manipulation results in memory leak. This vulnerability is reported as CVE-2023-53190. The attacker must have access to the local network to execute the attack. No exploit exists. It is advisable to upgrade the affected component.
- CVE-2023-53186 | Linux Kernel up to 5.15.107/6.1.24/6.2.11 page_pool reference count (EUVD-2023-59790 / Nessus ID 270112)by vuldb.com on December 2, 2025 at 5:50 am
A vulnerability described as critical has been identified in Linux Kernel up to 5.15.107/6.1.24/6.2.11. Impacted is the function page_pool. Executing manipulation can lead to improper update of reference count. The identification of this vulnerability is CVE-2023-53186. The attack needs to be done within the local network. There is no exploit available. Upgrading the affected component is recommended.
- CVE-2023-53188 | Linux Kernel up to 5.4.292/5.10.236/5.15.180/6.1.24/6.2.11 Veth Interface unregister_netdevice_many_notify infinite loop (EUVD-2023-59788 / Nessus ID 276910)by vuldb.com on December 2, 2025 at 5:50 am
A vulnerability classified as critical has been found in Linux Kernel up to 5.4.292/5.10.236/5.15.180/6.1.24/6.2.11. The affected element is the function unregister_netdevice_many_notify of the component Veth Interface. The manipulation leads to infinite loop. This vulnerability is referenced as CVE-2023-53188. The attack needs to be initiated within the local network. No exploit is available. It is recommended to upgrade the affected component.
- CVE-2023-53189 | Linux Kernel up to 6.4.4 addrconf_mod_rs_timer reference count (EUVD-2023-59787)by vuldb.com on December 2, 2025 at 5:50 am
A vulnerability was found in Linux Kernel up to 6.4.4. It has been rated as critical. This impacts the function addrconf_mod_rs_timer. The manipulation leads to improper update of reference count. This vulnerability is documented as CVE-2023-53189. The attack requires being on the local network. There is not any exploit available. Upgrading the affected component is advised.
- CVE-2023-53187 | Linux Kernel btrfs_create_pending_block_groups reference count (EUVD-2023-59789 / Nessus ID 265184)by vuldb.com on December 2, 2025 at 5:50 am
A vulnerability, which was classified as critical, has been found in Linux Kernel. The affected element is the function btrfs_create_pending_block_groups. This manipulation causes improper update of reference count. The identification of this vulnerability is CVE-2023-53187. The attack needs to be done within the local network. There is no exploit available. Applying a patch is the recommended action to fix this issue.
- CVE-2023-53185 | Linux Kernel up to 6.4.3 wifi privilege escalation (EUVD-2023-59791 / Nessus ID 274937)by vuldb.com on December 2, 2025 at 5:50 am
A vulnerability was found in Linux Kernel up to 6.4.3. It has been declared as critical. This affects an unknown function of the component wifi. Executing manipulation can lead to privilege escalation. This vulnerability is registered as CVE-2023-53185. The attack requires access to the local network. No exploit is available. It is recommended to upgrade the affected component.
- CVE-2023-53183 | Linux Kernel up to 5.15.126/6.1.45/6.4.10 btrfs prepare_to_merge assertion (EUVD-2023-59793 / Nessus ID 276910)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability marked as critical has been reported in Linux Kernel up to 5.15.126/6.1.45/6.4.10. This issue affects the function prepare_to_merge of the component btrfs. Performing manipulation results in reachable assertion. This vulnerability was named CVE-2023-53183. The attack needs to be approached within the local network. There is no available exploit. It is suggested to upgrade the affected component.
- CVE-2023-53193 | Linux Kernel up to 6.1.28/6.2.15/6.3.2 amdgpu_irq_put information disclosure (EUVD-2023-59783)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.28/6.2.15/6.3.2. Affected by this issue is the function amdgpu_irq_put. Such manipulation leads to information disclosure. This vulnerability is traded as CVE-2023-53193. Access to the local network is required for this attack to succeed. There is no exploit available. The affected component should be upgraded.
- CVE-2023-53195 | Linux Kernel up to 6.1.38/6.4.3 mlxsw mlxsw_m_linecards_init memory leak (EUVD-2023-59781)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.38/6.4.3. This affects the function mlxsw_m_linecards_init of the component mlxsw. Performing manipulation results in memory leak. This vulnerability is known as CVE-2023-53195. Access to the local network is required for this attack. No exploit is available. It is suggested to upgrade the affected component.
- CVE-2023-53194 | Linux Kernel up to 5.15.112/6.1.80/6.3.3 ntfs3 indx_get_root use after free (EUVD-2023-59782)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.112/6.1.80/6.3.3. The impacted element is the function indx_get_root of the component ntfs3. Such manipulation leads to use after free. This vulnerability is referenced as CVE-2023-53194. The attack needs to be initiated within the local network. No exploit is available. You should upgrade the affected component.
- CVE-2023-53191 | Linux Kernel up to 6.2.2 alpine-msi of_irq_find_parent reference count (EUVD-2023-59785 / Nessus ID 265224)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability identified as critical has been detected in Linux Kernel up to 6.2.2. Affected by this vulnerability is the function of_irq_find_parent of the component alpine-msi. This manipulation causes improper update of reference count. This vulnerability appears as CVE-2023-53191. The attacker needs to be present on the local network. There is no available exploit. You should upgrade the affected component.
- CVE-2025-13554 | Campcodes Supplier Management System 1.0 Login /index.php txtUsername sql injection (EUVD-2025-198573)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability categorized as critical has been discovered in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. This vulnerability is referenced as CVE-2025-13554. It is possible to launch the attack remotely. Furthermore, an exploit is available.
- CVE-2025-13555 | Campcodes School File Management System 1.0 Login /index.php stud_no sql injection (EUVD-2025-198575)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability identified as critical has been detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing manipulation of the argument stud_no results in sql injection. This vulnerability is identified as CVE-2025-13555. The attack can be initiated remotely. Additionally, an exploit exists.
- CVE-2025-13564 | SourceCodester Pre-School Management System 1.0 FilehelperController.php removefile filepath denial of service (EUVD-2025-198583)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability, which was classified as problematic, has been found in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. This vulnerability is reported as CVE-2025-13564. The attack is possible to be carried out remotely. Moreover, an exploit is present.
- CVE-2025-13567 | itsourcecode COVID Tracking System 1.0 ?page=establishment sql injection (EUVD-2025-198584)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability was found in itsourcecode COVID Tracking System 1.0 and classified as critical. This affects an unknown function of the file /admin/?page=establishment. The manipulation of the argument ID results in sql injection. This vulnerability is known as CVE-2025-13567. It is possible to launch the attack remotely. Furthermore, an exploit is available.
- CVE-2025-13568 | itsourcecode COVID Tracking System 1.0 /admin/?page=people sql injection (EUVD-2025-198587)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability was found in itsourcecode COVID Tracking System 1.0. It has been classified as critical. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument ID causes sql injection. This vulnerability is handled as CVE-2025-13568. The attack can be initiated remotely. Additionally, an exploit exists.
- CVE-2025-13569 | itsourcecode COVID Tracking System 1.0 /admin/?page=city sql injection (EUVD-2025-198586)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability was found in itsourcecode COVID Tracking System 1.0. It has been declared as critical. Affected is an unknown function of the file /admin/?page=city. Such manipulation of the argument ID leads to sql injection. This vulnerability is uniquely identified as CVE-2025-13569. The attack can be launched remotely. Moreover, an exploit is present.
- CVE-2025-13570 | itsourcecode COVID Tracking System 1.0 /admin/?page=state sql injection (EUVD-2025-198588)by vuldb.com on December 2, 2025 at 5:12 am
A vulnerability was found in itsourcecode COVID Tracking System 1.0. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file /admin/?page=state. Performing manipulation of the argument ID results in sql injection. This vulnerability was named CVE-2025-13570. The attack may be initiated remotely. In addition, an exploit is available.





