Author: Angelo Barbosa

CVE-2025-23205 | Jupyter nbgrader 0.9.4 exposure of resource

A vulnerability was found in Jupyter nbgrader 0.9.4. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to exposure of resource. This vulnerability was named CVE-2025-23205. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-23202 | devycreates Bible-Module up to 0.0.2 FetchVerse/FetchPassage injection

A vulnerability was found in devycreates Bible-Module up to 0.0.2. It has been classified as critical. This affects the function FetchVerse/FetchPassage. The manipulation leads to injection. This vulnerability is uniquely identified as CVE-2025-23202. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-23206 | aws aws-cdk 2.148.1 IAM OIDC Custom Resource Provider Package tls.connect signature verification

A vulnerability was found in aws aws-cdk 2.148.1 and classified as problematic. Affected by this issue is the function tls.connect of the component IAM OIDC Custom Resource Provider Package. The manipulation leads to improper verification of cryptographic signature. This vulnerability is handled as CVE-2025-23206. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-13524 | obsproject OBS Studio up to 30.0.2 on Windows untrusted search path

A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to untrusted search path. This vulnerability is known as CVE-2024-13524. The attack needs to be approached locally. There is no exploit available. The vendor disagrees that this issue is “something worth reporting, as every attack surface requires privileged access/user compromise”. It is recommended to apply a patch to fix this issue. The vendor disagrees that this issue is “something worth reporting, as every attack surface requires privileged access/user...

Read More

CVE-2025-0560 | CampCodes School Management Software 1.0 Photo Gallery Page /photo-gallery Description cross site scripting

A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /photo-gallery of the component Photo Gallery Page. The manipulation of the argument Description leads to cross site scripting. This vulnerability is traded as CVE-2025-0560. It is possible to launch the attack remotely. Furthermore, there is an exploit...

Read More