9
CVE-2025-30041 - Missing authentication in APIs returning statistical data along with session IDs
The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" expose data containing session IDs.
9
CVE-2025-30040 - Missing authentication in API returning request logs containing session IDs
The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/userlogxls.pl" endpoint.
9
CVE-2025-30039 - Missing authentication in API returning a list of all active sessions
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges.
7.3
CVE-2025-30038 - Session ID leakage in Zone.Identifier of downloaded files
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.
8.8
CVE-2025-30037 - Missing authentication in APIs allowing data retrieval and modification
The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publicly accessible without authentication to any host able to reach the application server on port 443/tcp.
8.8
CVE-2025-30036 - Stored XSS permitting session takeover of arbitrary user
Stored XSS vulnerability exists in the "OddziaΕ" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.
9.4
CVE-2025-2313 - RCE via Print.pl in uhcPrintServerPrint
In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.
6.5
CVE-2021-4459 - SMA: Directory Traversal in Sunny Boy <3.10.27.R
An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
6.3
CVE-2025-9514 - macrozheng mall Registration weak password
A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be diffβ¦
8.5
CVE-2025-57797 -
Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vulnerability is exploited, an authenticated local attacker may escalate privileges and execute an arbitrary command.