A vulnerability was found in Linux Kernel up to 6.6.68/6.12.7. It has been declared as problematic. This vulnerability affects the function pci_msi_setup_msi_irqs. Such manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2024-56760. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.7. Impacted is the function btrfs_cow_block of the file defrag.c. Executing manipulation can lead to use after free.
The identification of this vulnerability is CVE-2024-56759. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.12.7. The affected element is the function relocate_one_folio of the component btrfs. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2024-56758. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in RainyGao DocSys up to 2.02.36. It has been rated as critical. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal.
This vulnerability is identified as CVE-2025-11630. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, was found in HCL Unica Platform up to 25.1. This vulnerability affects unknown code. Executing manipulation can lead to sensitive cookie without secure attribute.
This vulnerability appears as CVE-2025-52614. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.175/6.1.123/6.6.69/6.12.8. Affected is the function in_atomic. The manipulation results in stack-based buffer overflow.
This vulnerability is reported as CVE-2024-57903. The attacker must have access to the local network to execute the attack. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.7. It has been rated as problematic. This issue affects some unknown processing of the component Bluetooth. Performing manipulation results in denial of service.
This vulnerability was named CVE-2024-56757. The attack may be carried out on the physical device. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability has been found in Linux Kernel up to 6.12.8 and classified as critical. This affects the function vlan_get_protocol_dgram of the file net/core/skbuff.c. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-57901. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
A vulnerability classified as critical was found in Linux Kernel up to 6.12.8. This affects the function vlan_get_tci of the file net/core/skbuff.c of the component af_packet. Executing manipulation can lead to denial of service.
This vulnerability is registered as CVE-2024-57902. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.8. Impacted is the function nf_register_net_hooks in the library include/linux/rhashtable.h. This manipulation causes use after free.
This vulnerability is tracked as CVE-2024-57900. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in HCL MaxAI Assistant. Affected by this vulnerability is an unknown functionality of the component Special Character Handler. Such manipulation leads to basic cross site scripting.
This vulnerability is traded as CVE-2025-31992. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in HCL Unica up to 12.1.10 and classified as problematic. This affects an unknown part. Executing manipulation can lead to exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is handled as CVE-2025-52616. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. It has been classified as critical. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection.
The identification of this vulnerability is CVE-2025-11628. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability labeled as critical has been found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of the argument firstname results in sql injection.
This vulnerability is identified as CVE-2025-11667. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability marked as critical has been reported in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of the argument Password causes sql injection.
This vulnerability is tracked as CVE-2025-11668. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability was found in Campcodes Online Beauty Parlor Management System 1.0. It has been declared as critical. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-11664. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in D-Link DAP-2695 2.00RC131. It has been rated as critical. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-11665. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password.
The identification of this vulnerability is CVE-2025-11666. The attack can only be executed locally. Furthermore, there is an exploit available.