CVE-2025-6500
published 2025-06-23CVE-2025-6500: A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.0th percentile
A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /php_action/editCategories.php. The manipulation of the argument editCategoriesName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | inventory_management_system | — | — |
| github.com | authzed_spicedb | >= 0 < 1.45.2 | 1.45.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco5.5MEDIUM
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SpiceDB WriteRelationships fails silently if payload is too big
ghsa·2025-11-13
CVE-2025-64529 [LOW] CWE-770 SpiceDB WriteRelationships fails silently if payload is too big
SpiceDB WriteRelationships fails silently if payload is too big
### Impact
Users who:
1. Use the exclusion operator somewhere in their authorization schema.
1. Have configured their SpiceDB server such that `--write-relationships-max-updates-per-call` is bigger than 6500.
1. Issue calls to WriteRelationships with a large enough number of updates that cause the payload to be bigger than what their datastore allows.
Users will:
1. Receive a successful response from their `WriteRelationships` call, when in reality that call failed.
2. Receive incorrect permission check results, if those relationships had to be read to resolve the relation involving the exclusion.
### Patches
Upgrade to v.145.2.
### Workarounds
Set `--write-relationships-max-updates-per-call` to `1000`.
GHSA
GHSA-rx9q-3622-r9jv: A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1
ghsa_unreviewed·2025-06-23
CVE-2025-6500 [MEDIUM] CWE-74 GHSA-rx9q-3622-r9jv: A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1
A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /php_action/editCategories.php. The manipulation of the argument editCategoriesName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Cisco
Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
vendor_cisco·2025-08-27·CVSS 5.5
CVE-2025-20290 [MEDIUM] CWE-200 Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive information.
This vulnerability is due to improper logging of sensitive information. An attacker could exploit this vulnerability by accessing log files on the file system where they are stored. A successful exploit could allow the attacker to access sensitive information, such as stored credentials.
Note: To access the log files on Cisco Nexus devices that are affecte
Cisco
Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20290 Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
CVE-2025-20290: Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive information. This vulnerability is due to improper logging of sensitive information. An attacker could exploit this vulnerability by accessing log files on the file system where they are stored. A successful exploit could allow the attacker to access sensitive information, such as stored credentials. Note: To access the log files on Cisco Nexus devices that a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-23
Published