CVE-2025-36513 |
Description: Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
June 6th, 2025 (2 days ago)
|
CVE-2025-5733 |
Description: The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
CVSS: MEDIUM (5.3) EPSS Score: 0.02%
June 6th, 2025 (2 days ago)
|
CVE-2025-5721 |
Description: A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Es wurde eine problematische Schwachstelle in SourceCodester Student Result Management System 1.0 gefunden. Hiervon betroffen ist ein unbekannter Codeblock der Datei /script/academic/core/update_profile der Komponente Profile Setting Page. Durch das Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS: MEDIUM (4.8) EPSS Score: 0.03%
June 6th, 2025 (2 days ago)
|
CVE-2025-5719 |
Description: The wallet has an authentication bypass vulnerability that allows access to specific pages.
CVSS: MEDIUM (5.1) EPSS Score: 0.02%
June 6th, 2025 (2 days ago)
|
CVE-2025-5716 |
Description: A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Es wurde eine kritische Schwachstelle in SourceCodester Open Source Clinic Management System 1.0 entdeckt. Dabei betrifft es einen unbekannter Codeteil der Datei /login.php. Durch Manipulation des Arguments email mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS: MEDIUM (6.9) EPSS Score: 0.03%
June 6th, 2025 (2 days ago)
|
CVE-2025-5714 |
Description: A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as problematic. This affects an unknown part of the file /sys/up.upload.php of the component Profile Information Update. The manipulation of the argument nomeArquivo leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Es wurde eine Schwachstelle in SoluçõesCoop iSoluçõesWEB bis 20250516 ausgemacht. Sie wurde als problematisch eingestuft. Es betrifft eine unbekannte Funktion der Datei /sys/up.upload.php der Komponente Profile Information Update. Dank Manipulation des Arguments nomeArquivo mit unbekannten Daten kann eine path traversal-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
CVSS: MEDIUM (5.3) EPSS Score: 0.04%
June 6th, 2025 (2 days ago)
|
CVE-2024-46941 |
Description: SystemUI has an incorrect component protection setting, which allows access to specific information.
CVSS: MEDIUM (4.8) EPSS Score: 0.01%
June 6th, 2025 (2 days ago)
|
CVE-2024-56343 |
Description: IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request.
CVSS: MEDIUM (4.3) EPSS Score: 0.04%
June 6th, 2025 (2 days ago)
|
CVE-2024-56342 |
Description: IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
June 6th, 2025 (2 days ago)
|
CVE-2024-22330 |
Description: IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
CVSS: MEDIUM (5.9) EPSS Score: 0.03%
June 6th, 2025 (2 days ago)
|