A vulnerability was found in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. It has been classified as problematic. This impacts an unknown function of the file /map.php of the component HTTP GET Request Handler. Performing manipulation of the argument trid results in cross site scripting.
This vulnerability is identified as CVE-2025-11291. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in CRMEB up to 5.6.1 and classified as critical. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key
.
This vulnerability is referenced as CVE-2025-11290. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab and classified as problematic. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template Management Page. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-11289. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.194/5.15.131/6.1.52/6.4.15/6.5.2. The affected element is the function some_lookup_func of the component bpf. The manipulation results in improper update of reference count.
This vulnerability was named CVE-2023-53585. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.10.172/5.15.98/6.1.15/6.2.2. Impacted is the function dc_construct_ctx of the component drm. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2023-53605. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 5.10.179/5.15.110/6.1.27/6.2.14/6.3.1. This issue affects some unknown processing of the component scsi. Executing manipulation can lead to deserialization.
This vulnerability is handled as CVE-2023-53586. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Linux Kernel up to 5.10.187/5.15.120/6.1.38/6.3.12/6.4.3. This vulnerability affects the function dax_mapping_release of the file kernel/locking/lockdep.c. Performing manipulation results in use after free.
This vulnerability is known as CVE-2023-53613. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.