A vulnerability was found in run-llama llama_index up to 0.12.x on Linux. It has been rated as problematic. This affects the function get_cache_dir of the file /tmp/llama_index. The manipulation leads to creation of temporary file with insecure permissions.
This vulnerability is uniquely identified as CVE-2025-7647. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.2.6/18.3.2/18.4.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component GraphQL Endpoint. Executing manipulation can lead to allocation of resources.
This vulnerability is handled as CVE-2025-8014. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of the component Error Message Handler. Performing manipulation of the argument Error results in cross site scripting.
This vulnerability is known as CVE-2025-11125. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
A vulnerability was found in code-projects Project Monitoring System 1.0 and classified as problematic. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting.
This vulnerability is traded as CVE-2025-11124. The attack may be launched remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as critical. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes stack-based buffer overflow.
This vulnerability appears as CVE-2025-11123. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow.
This vulnerability is reported as CVE-2025-11122. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability, which was classified as critical, has been found in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection.
This vulnerability is documented as CVE-2025-11121. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2025-11120. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability classified as problematic has been found in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting.
This vulnerability is cataloged as CVE-2025-11119. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.