5.5

CVSS4.0

CVE-2025-48374 - zot logs secrets

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into the container stdoutโ€ฆ

๐Ÿ“… Published: May 22, 2025, 8:43 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-48373 - Schule Has Client-Side Role-Based Access Control (RBAC) Bypass Vulnerability

Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the value of data.role isโ€ฆ

๐Ÿ“… Published: May 22, 2025, 8:39 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 2:12 p.m.

6.6

CVSS4.0

CVE-2025-48372 - Schule Has Insecure OTP Length, is Susceptible to Brute-Force Attacks

Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000โ€“9999) results in only 9000 possible combinationโ€ฆ

๐Ÿ“… Published: May 22, 2025, 8:38 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 2:15 p.m.

0.0

CVE-2025-5097 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: May 22, 2025, 8:30 p.m. ๐Ÿ”„ Last Modified: June 7, 2025, 11:15 p.m.

6.1

CVSS3.1

CVE-2024-5962 - Reflected Cross-Site Scripting (XSS) in Authentication Endpoint of Multiple WSO2 Products Due to Miโ€ฆ

A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the authentication flow, potentially leadiโ€ฆ

๐Ÿ“… Published: May 22, 2025, 7:34 p.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 1:57 p.m.

5.8

CVSS3.1

CVE-2024-7487 - Improper Authentication in WSO2 Identity Server 7.0.0 Allows Bypass of App-Native Authentication

An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the client verification โ€ฆ

๐Ÿ“… Published: May 22, 2025, 7:03 p.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 1:57 p.m.

4.6

CVSS3.1

CVE-2024-7103 - Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server 7.0.0 Sub-Organization Login Flow

A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modificationsโ€ฆ

๐Ÿ“… Published: May 22, 2025, 6:41 p.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 1:57 p.m.

7.1

CVSS4.0

CVE-2024-51552 - Weak Password Storage

Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

๐Ÿ“… Published: May 22, 2025, 6:38 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2024-13958 - Stored Cross Site Scripting

Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

๐Ÿ“… Published: May 22, 2025, 6:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-13957 - SSRF Server Side Request Forgery

SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

๐Ÿ“… Published: May 22, 2025, 6:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5282 of 34,919
ยซ previous page ยป next page
Filters