NA - CVE-2025-27454 - The application is vulnerable to cross-site...
The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did not intend. The request uses the victim's...
NA - CVE-2025-27455 - The web application is vulnerable to...
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user...
NA - CVE-2025-27456 - The SMB server's login mechanism does not...
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
NA - CVE-2025-27458 - The VNC authentication mechanism bases on a...
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to the client, is...
NA - CVE-2025-27459 - The VNC application stores its passwords...
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
NA - CVE-2025-27460 - The hard drives of the device are not encrypted...
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating...
Medium - CVE-2025-2540 - Multiple plugins for WordPress are vulnerable...
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input...