px

4 exploits Active since Oct 2025
CVE-2025-11343 WRITEUP HIGH WRITEUP
code-projects Student Crud Operation <3.3 - SQL Injection
A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function of the file delete.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
CVSS 7.3
CVE-2025-11347 WRITEUP HIGH WRITEUP
code-projects Student Crud Operation <3.3 - Unrestricted Upload
A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Student Page. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been made public and could be used.
CVSS 7.3
CVE-2025-11432 WRITEUP HIGH WRITEUP
itsourcecode Leave Management System 1.0 - SQL Injection
A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
CVSS 7.3
CVE-2025-11433 WRITEUP LOW WRITEUP
itsourcecode Leave Management System 1.0 - XSS
A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query Parameter Handler. Performing a manipulation of the argument ID results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
CVSS 3.5