The Windows Start menu is getting its first major redesign since 2021 and will be rolled out to everyone with the November 11 Patch Tuesday update. [...]
A vulnerability was found in EverShop up to 2.0.1. It has been declared as problematic. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers.
This vulnerability was named CVE-2025-12919. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in SourceCodester Baby Care System 1.0. It has been declared as critical. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-12933. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in SourceCodester Baby Care System 1.0. It has been classified as critical. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of the argument msgid causes sql injection.
This vulnerability is handled as CVE-2025-12932. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in SourceCodester Food Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection.
This vulnerability is known as CVE-2025-12931. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability has been found in SourceCodester Food Ordering System 1.0 and classified as critical. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2025-12930. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.