5.7
CVE-2025-25209 - Rhcl: sharedsecretref can be used to leak secrets severity
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak thoseβ¦
5.7
CVE-2025-25208 - Rhcl: authorino denial of service through authpolicy with sharedsecretref severity
A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster
9.8
CVE-2025-22974 -
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
6.5
CVE-2024-53542 -
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.
6.5
CVE-2024-57608 -
An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
5.3
CVE-2025-1598 - SourceCodester Best Church Management Software asset_crud.php unrestricted upload
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/asset_crud.php. The manipulation of the argument photo1 leads to unrestricted upload. The attack can bβ¦
5.1
CVE-2025-1597 - SourceCodester Best Church Management Software redirect.php cross site scripting
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/redirect.php. The manipulation of the argument a leads to cross site scripting. It is possible to launch the attack remotely. Thβ¦
6.9
CVE-2025-1596 - SourceCodester Best Church Management Software fpassword.php sql injection
A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has beeβ¦
7.1
CVE-2025-22635 - WordPress Eventer - WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site β¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Eventer eventer allows Reflected XSS.This issue affects Eventer: from n/a through < 3.9.9.
0.0
CVE-2025-22633 - WordPress Give β Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in StellarWP Give β Divi Donation Modules give-donation-modules-for-divi allows Retrieve Embedded Sensitive Data.This issue affects Give β Divi Donation Modules: from n/a through <= 2.0.0.