5.3
CVE-2025-9461 - diyhi bbs File Compression FilePackageManageAction.java information disclosure
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression Handler. This manipulation of the argument idGroup causes information disclosure. Re…
6.9
CVE-2025-9444 - 1000projects Online Project Report Submission and Evaluation System delete_group_student.php sql in…
A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/delete_group_student.php. The manipulation of the argument batch_id leads to sql injection. The attack can be initiated…
8.7
CVE-2025-9443 - Tenda CH22 editUserName formeditUserName buffer overflow
A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /goform/editUserName. Executing manipulation of the argument new_account can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and ma…
5.3
CVE-2025-9440 - 1000projects Online Project Report Submission and Evaluation System add_title.php cross site script…
A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_title.php. Such manipulation of the argument Title leads to cross site scripting. The attack may be perf…
5.3
CVE-2025-9439 - 1000projects Online Project Report Submission and Evaluation System edit_faculty.php cross site scr…
A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unknown functionality of the file /rse/admin/edit_faculty.php?id=2. This manipulation of the argument Name causes cross site scripting. The attack is possi…
7
CVE-2025-8447 - Incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed read-…
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker needed to know the na…
5.3
CVE-2025-9438 - 1000projects Online Project Report Submission and Evaluation System add_student.php cross site scri…
A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of the file /admin/add_student.php. The manipulation of the argument address results in cross site scripting. The attack can be executed remotely. The expl…
5.3
CVE-2025-9434 - 1000projects Online Project Report Submission and Evaluation System edit_title.php cross site scrip…
A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the file /admin/edit_title.php?id=1. Executing manipulation of the argument desc can lead to cross site scripting. The attack may be launched remotely. The …
5.3
CVE-2025-9433 - mtons mblog Admin Panel list cross site scripting
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made …
5.3
CVE-2025-9432 - mtons mblog Admin Panel list cross site scripting
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclose…