4.8

CVSS4.0

CVE-2025-11083 - GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public an…

πŸ“… Published: Sept. 27, 2025, 11:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 4:52 p.m.

4.8

CVSS4.0

CVE-2025-11082 - GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be …

πŸ“… Published: Sept. 27, 2025, 10:32 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 4:52 p.m.

4.8

CVSS4.0

CVE-2025-11081 - GNU Binutils objdump.c dump_dwarf_section out-of-bounds

A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f…

πŸ“… Published: Sept. 27, 2025, 10:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 4:51 p.m.

5.3

CVSS4.0

CVE-2025-11080 - zhuimengshaonian wisdom-education ExamInfoController.java selectStudentExamInfoList improper author…

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamInfoController.java. Such manipulation of the argument subjectId leads to…

πŸ“… Published: Sept. 27, 2025, 9:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-11079 - Campcodes Farm Management System file information disclosure

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file and directory information exposure. The attack may be performed from remote. The exploit has been released to the public and may be exp…

πŸ“… Published: Sept. 27, 2025, 9:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 3 p.m.

5.3

CVSS4.0

CVE-2025-11078 - itsourcecode Open Source Job Portal controller.php unrestricted upload

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation of the argument photo leads to unrestricted upload. The attack is possible to be carried out r…

πŸ“… Published: Sept. 27, 2025, 8:32 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 2:59 p.m.

6.9

CVSS4.0

CVE-2025-11077 - Campcodes Online Learning Management System add_content.php sql injection

A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed…

πŸ“… Published: Sept. 27, 2025, 8:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 2:57 p.m.

6.9

CVSS4.0

CVE-2025-11076 - Campcodes Online Learning Management System edit_teacher.php sql injection

A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument department results in sql injection. Remote exploitation of the attack is possible. The exploit has been made p…

πŸ“… Published: Sept. 27, 2025, 7:32 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 2:57 p.m.

6.9

CVSS4.0

CVE-2025-11075 - Campcodes Online Learning Management System de_activate.php sql injection

A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and …

πŸ“… Published: Sept. 27, 2025, 7:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 2:55 p.m.

6.9

CVSS4.0

CVE-2025-11074 - code-projects Project Monitoring System login.php sql injection

A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument username/password causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 27, 2025, 6:32 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.
Total resulsts: 349182
Page 3654 of 34,919
Β« previous page Β» next page
Filters