CVE-2025-15029Critical· 9.8▾ MidnightImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: fro…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 2.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
13%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user.
This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.
awie >= 24.04.0, < 24.04.3awie >= 24.10.0, < 24.10.3awie >= 25.10.0, < 25.10.2Upgrade past the affected range:
awie 25.10.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15026Critical· 9.8Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.…
CVE-2025-5965High· 7.2In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup
CVE-2025-15410High· 7.3A vulnerability was identified in code-projects Online Guitar Store 1.0
CVE-2025-15420High· 7.3A security vulnerability has been detected in Yonyou KSOA 9.0
CVE-2025-15212Medium· 6.3A vulnerability was detected in code-projects Refugee Food Management System 1.0
CVE-2025-14258High· 7.3A vulnerability has been found in itsourcecode Student Management System 1.0