| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2025-66606 | 8.2 | high |
This product does not properly encode URLs. An attacker could tamper with web pages or execute malicious scripts.
|
| CVE-2025-66605 | 8.2 | high |
Since there are input fields on this web page with the autocomplete attribute enabled, the input content could be saved in the browser the user is using.
|
| CVE-2025-66602 | 8.2 | high |
The web server accepts access by IP address. When a worm that randomly searches for IP addresses intrudes into the network, it could potentially be attacked by the worm.
|
| CVE-2025-66603 | 8.2 | high |
The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out other attacks.
|
| CVE-2025-66595 | 8.2 | high |
This product is vulnerable to cross-site request forgery (CSRF). When a user accesses a link crafted by an attacker, the user's account could be compromised.
|
| CVE-2025-66600 | 8.2 | high |
This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in the middle (MITM) attack, communications with the web server could be sniffed.
|
| CVE-2025-66607 | 8.2 | high |
The response header contains an insecure setting. Users could be redirected to malicious sites by an attacker.
|
| CVE-2025-66608 | 8.2 | high |
This product fails to adequately validate URLs. An attacker could send maliciously crafted requests to gain unauthorized access to files on the web server.
|
| CVE-2025-66601 | 8.2 | high |
This product does not specify MIME types. When an attacker performs a content sniffing attack, malicious scripts could be executed.
|
| CVE-2025-66604 | 8.2 | high |
The library version could be displayed on the web page. This information could be exploited by an attacker for other attacks.
|
| CVE-2025-66597 | 8.2 | high |
This product supports weak cryptographic algorithms, potentially allowing an attacker to decrypt communications with the web server.
|
| CVE-2025-66596 | 8.2 | high |
No description available.
|
| CVE-2025-66594 | 8.2 | high |
Detailed messages are displayed on the error page. This information could be exploited by an attacker for other attacks.
|
| CVE-2025-66599 | 8.2 | high |
Physical paths could be displayed on web pages. This information could be exploited by an attacker for other attacks.
|
| CVE-2025-66598 | 8.2 | high |
This product supports old SSL/TLS versions, potentially allowing an attacker to decrypt communications with the web server.
|