Vulnerabilities
Vulnerable Software
Security Vulnerabilities
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-08-18
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4.
CVSS Score
7.2
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS Score
6.2
EPSS Score
0.0
Published
2025-08-18
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.
CVSS Score
8.8
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.
CVSS Score
3.7
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
CVSS Score
5.9
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-08-18
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-08-18
DIAEnergie - Reflected Cross-site Scripting
CVSS Score
6.1
EPSS Score
0.0
Published
2025-08-18
DIAEnergie - Reflected Cross-site Scripting
CVSS Score
6.1
EPSS Score
0.0
Published
2025-08-18


Contact Us

Shodan ® - All rights reserved