6.9
CVE-2025-8252 - code-projects Exam Form Submission delete_s5.php sql injection
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete_s5.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has beeโฆ
6.9
CVE-2025-8251 - code-projects Exam Form Submission delete_s4.php sql injection
A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s4.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The explโฆ
6.9
CVE-2025-8250 - code-projects Exam Form Submission update_s4.php sql injection
A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s4.php. The manipulation of the argument credits leads to sql injection. It is possible to launch the attack remotely. The exploit has beโฆ
6.9
CVE-2025-8249 - code-projects Exam Form Submission update_s3.php sql injection
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s3.php. The manipulation of the argument credits leads to sql injection. The attack may be initiated remotely. The exploiโฆ
6.9
CVE-2025-8248 - code-projects Online Ordering System signup.php sql injection
A vulnerability classified as critical was found in code-projects Online Ordering System 1.0. This vulnerability affects unknown code of the file /signup.php. The manipulation of the argument firstname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to tโฆ
8.8
CVE-2025-29534 -
An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root privileges. The issue stems from insufficient sanitization of user-supplied input in the /cgi-bin/cgi_vista.cgi execโฆ
5.9
CVE-2022-50237 - ed25519-dalek: ed25519-dalek: Private Key Extraction Vulnerability
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
5.5
CVE-2025-38495 - HID: core: ensure the allocated report buffer can contain the reserved report ID
In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account fโฆ
2.9
CVE-2023-53160 - sequoia-openpgp: Sequoia OpenPGP Array Access Panic
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
7.1
CVE-2025-38482 - comedi: das6402: Fix bit shift out of bounds
In the Linux kernel, the following vulnerability has been resolved: comedi: das6402: Fix bit shift out of bounds When checking for a supported IRQ number, the following test is used: /* IRQs 2,3,5,6,7, 10,11,15 are valid for "enhanced" mode */ if ((1 << it->options[1]) & 0x8cec) { However, `iโฆ