<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>jankesec CVE Showcase</title><description>Credited vulnerabilities discovered during authorized assessments and coordinated disclosure.</description><link>https://jankesec.com/</link><language>en-us</language><item><title>CVE-2025-6577: SQL Injection (SQLi)</title><link>https://jankesec.com/cves/2025-6577/</link><guid isPermaLink="true">https://jankesec.com/cves/2025-6577/</guid><description>An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Akıllı Ticaret&apos;s E-Commerce Website. Affects versions before 4.5.001. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. (Critical - Akıllı Ticaret E-Commerce Website)</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Akıllı Ticaret&apos;s E-Commerce Website. Affects versions before 4.5.001. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Target:&lt;/strong&gt; Akıllı Ticaret E-Commerce Website&lt;br/&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Critical (CVSS undefined)&lt;br/&gt;&lt;strong&gt;CWE:&lt;/strong&gt; CWE-89&lt;br/&gt;&lt;strong&gt;Credit:&lt;/strong&gt; Sevban Alp DÖNMEZ&lt;/p&gt;</content:encoded><category>Critical</category><category>CWE-89</category><category>Akıllı Ticaret E-Commerce Website</category></item><item><title>CVE-2025-4764: SQL Injection (SQLi)</title><link>https://jankesec.com/cves/2025-4764/</link><guid isPermaLink="true">https://jankesec.com/cves/2025-4764/</guid><description>An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. The CVE record marks versions through 22012026 as affected and notes that the vendor did not respond to the coordinated disclosure. NVD scores the issue 8.8 with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; the original TR-CERT CNA assessment of 8.0 remains preserved on the detail page. (High - Aida Computer Hotel Guest Hotspot)</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. The CVE record marks versions through 22012026 as affected and notes that the vendor did not respond to the coordinated disclosure. NVD scores the issue 8.8 with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; the original TR-CERT CNA assessment of 8.0 remains preserved on the detail page.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Target:&lt;/strong&gt; Aida Computer Hotel Guest Hotspot&lt;br/&gt;&lt;strong&gt;Severity:&lt;/strong&gt; High (CVSS undefined)&lt;br/&gt;&lt;strong&gt;CWE:&lt;/strong&gt; CWE-89&lt;br/&gt;&lt;strong&gt;Credit:&lt;/strong&gt; Sevban DÖNMEZ&lt;/p&gt;</content:encoded><category>High</category><category>CWE-89</category><category>Aida Computer Hotel Guest Hotspot</category></item><item><title>CVE-2025-7743: Cleartext Transmission of Sensitive Information</title><link>https://jankesec.com/cves/2025-7743/</link><guid isPermaLink="true">https://jankesec.com/cves/2025-7743/</guid><description>A Cleartext Transmission of Sensitive Information vulnerability (CWE-319) in Dolusoft Omaspot allows interception and privilege escalation. Affects versions before 12.09.2025. CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. (Critical - Dolusoft Omaspot)</description><pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A Cleartext Transmission of Sensitive Information vulnerability (CWE-319) in Dolusoft Omaspot allows interception and privilege escalation. Affects versions before 12.09.2025. CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Target:&lt;/strong&gt; Dolusoft Omaspot&lt;br/&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Critical (CVSS undefined)&lt;br/&gt;&lt;strong&gt;CWE:&lt;/strong&gt; CWE-319&lt;br/&gt;&lt;strong&gt;Credit:&lt;/strong&gt; Sevban Donmez&lt;/p&gt;</content:encoded><category>Critical</category><category>CWE-319</category><category>Dolusoft Omaspot</category></item><item><title>CVE-2025-7744: SQL Injection (SQLi)</title><link>https://jankesec.com/cves/2025-7744/</link><guid isPermaLink="true">https://jankesec.com/cves/2025-7744/</guid><description>An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Dolusoft Omaspot. Affects versions before 12.09.2025. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. (Critical - Dolusoft Omaspot)</description><pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Dolusoft Omaspot. Affects versions before 12.09.2025. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Target:&lt;/strong&gt; Dolusoft Omaspot&lt;br/&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Critical (CVSS undefined)&lt;br/&gt;&lt;strong&gt;CWE:&lt;/strong&gt; CWE-89&lt;br/&gt;&lt;strong&gt;Credit:&lt;/strong&gt; Sevban Donmez&lt;/p&gt;</content:encoded><category>Critical</category><category>CWE-89</category><category>Dolusoft Omaspot</category></item></channel></rss>