Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2025
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-01-28
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-01-28
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-01-27
CMSimple 5.16 allows the user to edit log.php file via print page.
CVSS Score
9.1
EPSS Score
0.001
Published
2025-01-27
CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-01-27
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-01-27
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-01-27
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-01-27
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.
CVSS Score
5.5
EPSS Score
0.0
Published
2025-01-27
This issue was addressed through improved state management. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-01-27


Contact Us

Shodan ® - All rights reserved