CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-57266

    Last Modified: 15 Apr 2026

    An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.

    Published: 29 Sept 2025
    7.5
    High

    CVE-2025-56234

    Last Modified: 15 Apr 2026

    AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA2000 has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be within the current receive window, which violates RFC5961. This flaw allows attackers to send multiple random TCP RST packets to hit the acceptable range of sequence numbers, thereby interrupting normal connections and causing a denial-of-service attack.

    Published: 29 Sept 2025
    3.5
    Low

    CVE-2025-55795

    Last Modified: 16 Oct 2025

    The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a higher user ID without proper verification. This results in the victim's email being reassigned to the attacker's account, causing the victim to be locked out immediately and unable to log in. The vulnerability leads to denial of service via account lockout but does not grant the attacker direct access to the victim's private data.

    Published: 29 Sept 2025
    6.8
    Medium

    CVE-2025-61659

    Last Modified: 15 Apr 2026

    bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.

    Published: 29 Sept 2025
    2.1
    Low

    CVE-2025-11125

    Last Modified: 15 Apr 2026

    A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of the component Error Message Handler. Performing manipulation of the argument Error results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

    Published: 28 Sept 2025
    2
    Low

    CVE-2025-11124

    Last Modified: 23 Oct 2025

    A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 28 Sept 2025
    7.4
    High

    CVE-2025-11123

    Last Modified: 3 Oct 2025

    A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used.

    Published: 28 Sept 2025
    7.4
    High

    CVE-2025-11122

    Last Modified: 3 Oct 2025

    A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11121

    Last Modified: 3 Oct 2025

    A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 28 Sept 2025
    7.4
    High

    CVE-2025-11120

    Last Modified: 3 Oct 2025

    A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11119

    Last Modified: 3 Oct 2025

    A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11118

    Last Modified: 3 Oct 2025

    A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument staffId leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

    Published: 28 Sept 2025
    7.4
    High

    CVE-2025-11117

    Last Modified: 3 Oct 2025

    A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the file /goform/GstDhcpSetSer. This manipulation of the argument dips causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11116

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. Other parameters might be affected as well.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11115

    Last Modified: 23 Oct 2025

    A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown functionality of the file /addtime.php. The manipulation of the argument starttime/endtime leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11114

    Last Modified: 2 Oct 2025

    A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicationForm.php. Executing manipulation of the argument absence[] can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11113

    Last Modified: 2 Oct 2025

    A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Other parameters might be affected as well.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11112

    Last Modified: 2 Oct 2025

    A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument First name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11111

    Last Modified: 2 Oct 2025

    A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/candidates_edit.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11110

    Last Modified: 2 Oct 2025

    A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/school_year.php. The manipulation of the argument school_year results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11109

    Last Modified: 2 Oct 2025

    A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11108

    Last Modified: 23 Oct 2025

    A vulnerability was determined in code-projects Simple Scheduling System 1.0. Impacted is an unknown function of the file /schedulingsystem/addroom.php. Executing manipulation of the argument room can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11107

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Simple Scheduling System 1.0. This issue affects some unknown processing of the file /schedulingsystem/addcourse.php. Performing manipulation of the argument corcode results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11106

    Last Modified: 23 Oct 2025

    A vulnerability has been found in code-projects Simple Scheduling System 1.0. This vulnerability affects unknown code of the file /schedulingsystem/addfaculty.php. Such manipulation of the argument falname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11105

    Last Modified: 23 Oct 2025

    A flaw has been found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /schedulingsystem/addsubject.php. This manipulation of the argument subcode causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11104

    Last Modified: 3 Oct 2025

    A vulnerability was detected in CodeAstro Electricity Billing System 1.0. Affected by this issue is some unknown functionality of the file /admin/bill.php. The manipulation of the argument uid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 28 Sept 2025
    2
    Low

    CVE-2025-11103

    Last Modified: 3 Oct 2025

    A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11102

    Last Modified: 3 Oct 2025

    A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/edit_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11101

    Last Modified: 3 Oct 2025

    A security flaw has been discovered in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the file /jobportal/admin/company/index.php?view=edit. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11100

    Last Modified: 2 Oct 2025

    A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11099

    Last Modified: 2 Oct 2025

    A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11098

    Last Modified: 2 Oct 2025

    A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11097

    Last Modified: 2 Oct 2025

    A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11096

    Last Modified: 2 Oct 2025

    A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulation of the argument target_addr can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11095

    Last Modified: 2 Oct 2025

    A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing manipulation of the argument delvalue results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11094

    Last Modified: 23 Oct 2025

    A security vulnerability has been detected in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/admin_product_details.php. Such manipulation of the argument prod_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11092

    Last Modified: 2 Oct 2025

    A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_switch_settings. This manipulation of the argument port causes command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

    Published: 28 Sept 2025
    7.4
    High

    CVE-2025-11091

    Last Modified: 3 Oct 2025

    A security flaw has been discovered in Tenda AC21 up to 16.03.08.16. Affected by this vulnerability is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11090

    Last Modified: 3 Oct 2025

    A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected is an unknown function of the file /admin/employee/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

    Published: 28 Sept 2025
    5.5
    Medium

    CVE-2025-11089

    Last Modified: 7 Oct 2025

    A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This impacts an unknown function of the file /Profilers/PriProfile/COUNT3s4.php. Executing manipulation of the argument cbranch can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

    Published: 28 Sept 2025
    2.1
    Low

    CVE-2025-11088

    Last Modified: 3 Oct 2025

    A weakness has been identified in itsourcecode Open Source Job Portal 1.0. Impacted is an unknown function of the file /admin/vacancy/index.php?view=edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

    Published: 27 Sept 2025
    1.9
    Low

    CVE-2025-11083

    Last Modified: 12 May 2026

    A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

    Published: 27 Sept 2025
    1.9
    Low

    CVE-2025-11082

    Last Modified: 12 May 2026

    A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

    Published: 27 Sept 2025
    1.9
    Low

    CVE-2025-11081

    Last Modified: 3 Oct 2025

    A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.

    Published: 27 Sept 2025
    2.1
    Low

    CVE-2025-11080

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of the argument subjectId leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 27 Sept 2025
    5.5
    Medium

    CVE-2025-11079

    Last Modified: 3 Oct 2025

    A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file and directory information exposure. The attack may be performed from remote. The exploit has been released to the public and may be exploited.

    Published: 27 Sept 2025
    2.1
    Low

    CVE-2025-11078

    Last Modified: 3 Oct 2025

    A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation of the argument photo leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

    Published: 27 Sept 2025
    5.5
    Medium

    CVE-2025-11077

    Last Modified: 3 Oct 2025

    A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 27 Sept 2025
    5.5
    Medium

    CVE-2025-11076

    Last Modified: 3 Oct 2025

    A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument department results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

    Published: 27 Sept 2025
    5.5
    Medium

    CVE-2025-11075

    Last Modified: 3 Oct 2025

    A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Sept 2025