Category: CVE

CVE-2025-23205 | Jupyter nbgrader 0.9.4 exposure of resource

A vulnerability was found in Jupyter nbgrader 0.9.4. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to exposure of resource. This vulnerability was named CVE-2025-23205. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-23202 | devycreates Bible-Module up to 0.0.2 FetchVerse/FetchPassage injection

A vulnerability was found in devycreates Bible-Module up to 0.0.2. It has been classified as critical. This affects the function FetchVerse/FetchPassage. The manipulation leads to injection. This vulnerability is uniquely identified as CVE-2025-23202. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-23206 | aws aws-cdk 2.148.1 IAM OIDC Custom Resource Provider Package tls.connect signature verification

A vulnerability was found in aws aws-cdk 2.148.1 and classified as problematic. Affected by this issue is the function tls.connect of the component IAM OIDC Custom Resource Provider Package. The manipulation leads to improper verification of cryptographic signature. This vulnerability is handled as CVE-2025-23206. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-13524 | obsproject OBS Studio up to 30.0.2 on Windows untrusted search path

A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to untrusted search path. This vulnerability is known as CVE-2024-13524. The attack needs to be approached locally. There is no exploit available. The vendor disagrees that this issue is “something worth reporting, as every attack surface requires privileged access/user compromise”. It is recommended to apply a patch to fix this issue. The vendor disagrees that this issue is “something worth reporting, as every attack surface requires privileged access/user...

Read More

CVE-2025-0560 | CampCodes School Management Software 1.0 Photo Gallery Page /photo-gallery Description cross site scripting

A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /photo-gallery of the component Photo Gallery Page. The manipulation of the argument Description leads to cross site scripting. This vulnerability is traded as CVE-2025-0560. It is possible to launch the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2025-0559 | Campcodes School Management Software 1.0 Create Id Card Page /create-id-card ID Card Title cross site scripting

A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This issue affects some unknown processing of the file /create-id-card of the component Create Id Card Page. The manipulation of the argument ID Card Title leads to cross site scripting. The identification of this vulnerability is CVE-2025-0559. The attack may be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2025-0558 | TDuckCloud tduck-platform up to 4.0 QueryProThemeRequest.java QueryProThemeRequest color sql injection

A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The manipulation of the argument color leads to sql injection. This vulnerability was named CVE-2025-0558. The attack can be initiated remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2025-0557 | Hyland Alfresco Community Edition up to 6.2.2 URL /share/s/ cross site scripting

A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2025-0557. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-13184 | Ultimate Toolkit Plugin up to 3.0.12 on WordPress Login Attempts Module sql injection

A vulnerability was found in Ultimate Toolkit Plugin up to 3.0.12 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality of the component Login Attempts Module. The manipulation leads to sql injection. This vulnerability is handled as CVE-2024-13184. The attack may be launched remotely. There is no exploit...

Read More

CVE-2025-23039 | Caido 0.45.0 HTTP Request cross site scripting

A vulnerability was found in Caido 0.45.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2025-23039. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-57033 | WeGIA up to 3.1.x documentos_funcionario.php dados_addInfo cross site scripting

A vulnerability was found in WeGIA up to 3.1.x. It has been classified as problematic. Affected is an unknown function of the file documentos_funcionario.php. The manipulation of the argument dados_addInfo leads to cross site scripting. This vulnerability is traded as CVE-2024-57033. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More
Loading