CVE Vitrini
Yetkilendirilmiş testler sırasında bulunan ve koordineli bildirim ile raporlanan zafiyetler. En yeniden eskiye; varsa ilgili yazıya bağlantı içerir.
CVE-2025-6577
CNA 9.8SQL Injection (SQLi)
An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Akıllı Ticaret's E-Commerce Website. Affects versions before 4.5.001. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
CVE-2025-4764
NVD 8.8SQL Injection (SQLi)
An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection. The CVE record marks versions through 22012026 as affected and notes that the vendor did not respond to the coordinated disclosure. NVD scores the issue 8.8 with CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H; the original TR-CERT CNA assessment of 8.0 remains preserved on the detail page.
CVE-2025-7743
CNA 9.6Cleartext Transmission of Sensitive Information
A Cleartext Transmission of Sensitive Information vulnerability (CWE-319) in Dolusoft Omaspot allows interception and privilege escalation. Affects versions before 12.09.2025. CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
CVE-2025-7744
CNA 9.8SQL Injection (SQLi)
An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Dolusoft Omaspot. Affects versions before 12.09.2025. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
