6.9
CVE-2025-54885 - Thinbus generates insufficient entropy: 252 bits vs minimum 256 bits
Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instead of the intended bit length of the safe prime (defaulted toβ¦
7.1
CVE-2025-54882 - Himmelblau's Kerberos credential cache collection is world readable
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud TGT received during logon in the Kerberos credential cache. The created credential cache collection and received credentials arβ¦
4
CVE-2025-32094 -
An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two in-path Akamai serverβ¦
6.1
CVE-2024-52680 -
EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
8.8
CVE-2023-41524 -
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.
7.8
CVE-2025-50675 -
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to manipulate files within the directory, incluβ¦
7.4
CVE-2025-55138 -
LinkJoin through 882f196 mishandles token ownership in password reset.
9.8
CVE-2023-41526 -
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.
6.1
CVE-2025-54392 -
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
6.5
CVE-2024-42048 -
OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may reβ¦