6.9
CVE-2025-11660 - ProjectsAndPrograms School Management System uploadSllyabus.php unrestricted upload
A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue is some unknown functionality of the file /assets/uploadSllyabus.php. Such manipulation of the argument File leads to unrestricted upload. The attackโฆ
4.3
CVE-2025-31994 - HCL Unica Campaign is vulnerable to Reflected Cross-Site Scripting (XSS)
HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted weโฆ
5.3
CVE-2025-31996 - Unprotected files are impacting HCL Unica Platform
HCL Unica Platform is affected by unprotected files due to improper access controls. ย These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, infrastructure, or users.
6.9
CVE-2025-11659 - ProjectsAndPrograms School Management System uploadNotes.php unrestricted upload
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability is an unknown functionality of the file /assets/uploadNotes.php. This manipulation of the argument File causes unrestricted upload. Remote exploitatioโฆ
6.9
CVE-2025-11658 - ProjectsAndPrograms School Management System changeSllyabus.php unrestricted upload
A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown function of the file /assets/changeSllyabus.php. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotโฆ
6.9
CVE-2025-11657 - ProjectsAndPrograms School Management System createNotice.php unrestricted upload
A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impacts an unknown function of the file /assets/createNotice.php. The manipulation of the argument File leads to unrestricted upload. The attack may be iniโฆ
6.9
CVE-2025-11656 - ProjectsAndPrograms School Management System editNotes.php unrestricted upload
A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown function of the file /assets/editNotes.php. Executing manipulation of the argument File can lead to unrestricted upload. The attack can be launched โฆ
5.1
CVE-2025-11655 - Total.js Flow SVG File unrestricted upload
A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been releโฆ
6.9
CVE-2025-11654 - yousaf530 Inferno Online Clothing Store log.php sql injection
A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208. The affected element is an unknown function of the file /log.php. Such manipulation of the argument cemail/password leads to sql injection. It is possible to launch the attack rโฆ
8.1
CVE-2025-36087 - IBM Security Verify Access hard coded credentials
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communโฆ