1.8
CVE-2025-10650 - Improper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administraβ¦
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH.Β Affects non-production debug and internal development builds created between versions 2.5.0 andβ¦
6.7
CVE-2025-26503 - Buffer manipulation
A crafted system call argument can cause memory corruption.
6.5
CVE-2025-47906 - Unexpected paths returned from LookPath in os/exec
If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
6.9
CVE-2025-10687 - SourceCodester Responsive E-Learning System add_teacher.php sql injection
A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /admin/add_teacher.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and couldβ¦
0.0
CVE-2022-50403 - ext4: fix undefined behavior in bit shift for ext4_check_flag_values
In the Linux kernel, the following vulnerability has been resolved: ext4: fix undefined behavior in bit shift for ext4_check_flag_values Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below: UBSAN: shift-out-of-bounβ¦
5.3
CVE-2025-10676 - fuyang_lipengjun platform queryAll BrandController improper authorization
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be exploβ¦
5.3
CVE-2025-10675 - fuyang_lipengjun platform queryAll AttributeController improper authorization
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public β¦
0.0
CVE-2025-59672 -
Not used
0.0
CVE-2025-59678 -
Not used
0.0
CVE-2025-59676 -
Not used