Badge
11,371 badges added since 01 January 2025
ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

The Evergreen State College has been a leader in environmental studies for more than 50 years. MES is a master of environmental studies graduate program at Evergreen. Our students and graduates are innovative thinkers who approach environmental challenges with eagerness and ambition. Because the best environmental solutions come from a variety of perspectives, we accept all majors. Our students, who come from across the U.S. and abroad, represent a wide range of ages, cultures, and expertise. We’re located at the south end of the Salish Sea (Puget Sound) in Olympia, Washington, close to mountains, rivers, wetlands, forests, and shorelines. It’s the ideal location for studying and enjoying the natural environment. This page is a tool for sharing jobs, internships, events, and connecting with other members of the MES community. Have something you want to share with the MES community? Send an email to the Program Assistant, Trudy Rubick, at [email protected].

MES at The Evergreen State College A.I CyberSecurity Scoring

MESC

Company Details

Linkedin ID:

mesevergreen

Employees number:

2

Number of followers:

90

NAICS:

6113

Industry Type:

Higher Education

Homepage:

evergreen.edu

IP Addresses:

0

Company ID:

MES_2738040

Scan Status:

In-progress

AI scoreMESC Risk Score (AI oriented)

Between 650 and 699

https://images.rankiteo.com/companyimages/mesevergreen.jpeg
MESC Higher Education
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreMESC Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/mesevergreen.jpeg
MESC Higher Education
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

MESC Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsSupply Chain SourceIncident DetailsView
MES at The Evergreen State CollegeBreach8545/2025NA
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The Evergreen State College, a public liberal arts institution in Olympia, Washington, experienced a data breach between May 21, 2025, and June 10, 2025, due to unauthorized access to a legacy file share system containing sensitive student records. The breach exposed personally identifiable information (PII) of 7,727 Washington residents, including names, Social Security numbers, full dates of birth, and student ID numbers. The college confirmed the incident on October 1, 2025, and issued notification letters to affected individuals on October 17, 2025, while also reporting the breach to the Washington Attorney General. The compromised data poses significant risks of identity theft, financial fraud, and long-term reputational harm to victims. Evergreen offered 12 months of free credit monitoring (Experian IdentityWorks) to mitigate risks, but the exposure of SSNs and full birth dates heightens vulnerabilities for affected students. Legal firms, including Shamis & Gentile P.A., are investigating potential class-action lawsuits for compensation, citing negligence in securing legacy systems and delayed disclosure. The breach underscores systemic vulnerabilities in educational institutions’ cybersecurity practices, particularly in protecting highly sensitive student data from unauthorized access.

The Evergreen State College
Breach
Severity: 85
Impact: 4
Seen: 5/2025
Blog:
Supply Chain Source: NA
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: The Evergreen State College, a public liberal arts institution in Olympia, Washington, experienced a data breach between May 21, 2025, and June 10, 2025, due to unauthorized access to a legacy file share system containing sensitive student records. The breach exposed personally identifiable information (PII) of 7,727 Washington residents, including names, Social Security numbers, full dates of birth, and student ID numbers. The college confirmed the incident on October 1, 2025, and issued notification letters to affected individuals on October 17, 2025, while also reporting the breach to the Washington Attorney General. The compromised data poses significant risks of identity theft, financial fraud, and long-term reputational harm to victims. Evergreen offered 12 months of free credit monitoring (Experian IdentityWorks) to mitigate risks, but the exposure of SSNs and full birth dates heightens vulnerabilities for affected students. Legal firms, including Shamis & Gentile P.A., are investigating potential class-action lawsuits for compensation, citing negligence in securing legacy systems and delayed disclosure. The breach underscores systemic vulnerabilities in educational institutions’ cybersecurity practices, particularly in protecting highly sensitive student data from unauthorized access.

Ailogo

MESC Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for MESC

Incidents vs Higher Education Industry Average (This Year)

No incidents recorded for MES at The Evergreen State College in 2026.

Incidents vs All-Companies Average (This Year)

No incidents recorded for MES at The Evergreen State College in 2026.

Incident Types MESC vs Higher Education Industry Avg (This Year)

No incidents recorded for MES at The Evergreen State College in 2026.

Incident History — MESC (X = Date, Y = Severity)

MESC cyber incidents detection timeline including parent company and subsidiaries

MESC Company Subsidiaries

SubsidiaryImage

The Evergreen State College has been a leader in environmental studies for more than 50 years. MES is a master of environmental studies graduate program at Evergreen. Our students and graduates are innovative thinkers who approach environmental challenges with eagerness and ambition. Because the best environmental solutions come from a variety of perspectives, we accept all majors. Our students, who come from across the U.S. and abroad, represent a wide range of ages, cultures, and expertise. We’re located at the south end of the Salish Sea (Puget Sound) in Olympia, Washington, close to mountains, rivers, wetlands, forests, and shorelines. It’s the ideal location for studying and enjoying the natural environment. This page is a tool for sharing jobs, internships, events, and connecting with other members of the MES community. Have something you want to share with the MES community? Send an email to the Program Assistant, Trudy Rubick, at [email protected].

Loading...
similarCompanies

MESC Similar Companies

The Ohio State University

One of the largest universities in the United States, The Ohio State University is a leading research university and the model for Ohio's public higher education institutes. Founded in 1870 as a land-grant university, it consistently ranks as one of the top public universities in the United States.

Alma Mater Studiorum – Università di Bologna

Alma Mater Studiorum - Università di Bologna operates on the principle that every individual carries within themselves a unique and unrepeatable potential. Active listening and dialogue guide the work of the University of Bologna, which promotes, in all its activities, inclusion, equity, and dive

Arizona State University

ASU has developed a new model for the American research university, creating an institution committed to excellence, access and impact — the New American University. Nationally and internationally acclaimed, ASU ranks among the very best in nearly every critical measurement of student success, out

Carnegie Mellon University

Carnegie Mellon University founder Andrew Carnegie said: "My heart is in the work."​ No statement better captures the passion and drive of our people to make a real difference. At Carnegie Mellon, we're not afraid of the work. Our educational environment creates problem solvers, drivers of

Galileo Global Education

Galileo Global Education, world leader in independent higher education with 210,000 students, 61 schools and 106 campuses in 18 countries, placed employability and innovation at the heart of its strategy for 15 years. Galileo Global Education's mission is to enable everyone, regardless of their star

University of Houston

Founded in 1927, the University of Houston is the leading public research university in the vibrant international city of Houston. Each year, we educate more than 47,000 students in more than 250 undergraduate and graduate academic programs, on campus and online. UH awards over 10,000 degrees annual

University of Missouri-Columbia

We are Mizzou! Our distinct mission, as Missouri's only state-supported member of the Association of American Universities, is to provide all Missourians the benefits of a world-class research university. We are stewards and builders of a priceless state resource, a unique physical infrastructure an

Pontificia Universidad Católica de Chile

Founded in 1888, Pontificia Universidad Católica de Chile is currently one of the leading higher education institutions in Latin America. Approximately 22,000 students are enrolled in graduate and undergraduate programs, which encompass a wide range of disciplines and professional schools. Its fa

The California State University

The California State University is the largest system of four-year higher education in the country, with 22 campuses, 56,000 faculty and staff and more than 450,000 students. Created in 1960, the mission of the CSU is to provide high-quality, affordable education to meet the ever-changing needs of

newsone

MESC CyberSecurity News

January 24, 2026 09:51 PM
Kataria calls for team to boost cybersecurity

Punjab Governor and UT Administrator Gulab Chand Kataria on Saturday stressed the need to create a dedicated and trained team to strengthen...

January 24, 2026 07:00 PM
🔒 What is a VPN Portal- Learn why VPN portals are important for online security #VPNPortal #VPNSecurity #FreeVPNRisks #ssl #vpn #VPNSafety #VPNDisadvantages #VPNAndroid #CyberSecurity #OnlineSafety

January 24, 2026 02:35 PM
Germany news: Berlin vows aggressive cybersecurity stance

Berlin promises to take down bad cyber actors and a new report prompts questions of whether police should carry Tasers to keep them from...

January 24, 2026 11:30 AM
AgweekTV Full Show: Disappearing topsoil, bull genetics, virtual fencing, cybersecurity in ag

Disappearing topsoil is a big problem for land and bottom line. Expert advice for picking the best bull genetics. Keeping cattle right where...

January 24, 2026 10:46 AM
2026 CISO AI Risk Report

Introduction. Many security leaders didn't authorize AI expansion. It happened around them. Someone plugged in a copilot in a SaaS tool or...

January 24, 2026 10:00 AM
National Cyber Security Summit: Cybersecurity a strategic business risk

It's been a busy time for New Zealand's National Cyber Security Centre as it takes an unprecedentedly proactive posture to cyber threats.

January 24, 2026 09:48 AM
Data Deletion: Why Erasing Your Information Matters More Than Ever

Data deletion is a great way to reduce your digital footprint and lower the risk of cybercrime – here's a guide to deleting your data...

January 24, 2026 09:08 AM
Why Cybersecurity Works Better When Defenders Share Data

This post is also available in: עברית (Hebrew). Organizations are increasingly expected to share data across corporate boundaries, yet cybersecurity risks...

January 24, 2026 08:32 AM
Why AI is exposing the limits of automated security decision-making

When cybercriminals are designing ways to deliver malware, hiding payloads within files remains one of the most common and, for them,...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

MESC CyberSecurity History Information

Official Website of MES at The Evergreen State College

The official website of MES at The Evergreen State College is https://www.evergreen.edu/mes.

MES at The Evergreen State College’s AI-Generated Cybersecurity Score

According to Rankiteo, MES at The Evergreen State College’s AI-generated cybersecurity score is 683, reflecting their Weak security posture.

How many security badges does MES at The Evergreen State College’ have ?

According to Rankiteo, MES at The Evergreen State College currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Has MES at The Evergreen State College been affected by any supply chain cyber incidents ?

According to Rankiteo, MES at The Evergreen State College has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.

Does MES at The Evergreen State College have SOC 2 Type 1 certification ?

According to Rankiteo, MES at The Evergreen State College is not certified under SOC 2 Type 1.

Does MES at The Evergreen State College have SOC 2 Type 2 certification ?

According to Rankiteo, MES at The Evergreen State College does not hold a SOC 2 Type 2 certification.

Does MES at The Evergreen State College comply with GDPR ?

According to Rankiteo, MES at The Evergreen State College is not listed as GDPR compliant.

Does MES at The Evergreen State College have PCI DSS certification ?

According to Rankiteo, MES at The Evergreen State College does not currently maintain PCI DSS compliance.

Does MES at The Evergreen State College comply with HIPAA ?

According to Rankiteo, MES at The Evergreen State College is not compliant with HIPAA regulations.

Does MES at The Evergreen State College have ISO 27001 certification ?

According to Rankiteo,MES at The Evergreen State College is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of MES at The Evergreen State College

MES at The Evergreen State College operates primarily in the Higher Education industry.

Number of Employees at MES at The Evergreen State College

MES at The Evergreen State College employs approximately 2 people worldwide.

Subsidiaries Owned by MES at The Evergreen State College

MES at The Evergreen State College presently has no subsidiaries across any sectors.

MES at The Evergreen State College’s LinkedIn Followers

MES at The Evergreen State College’s official LinkedIn profile has approximately 90 followers.

NAICS Classification of MES at The Evergreen State College

MES at The Evergreen State College is classified under the NAICS code 6113, which corresponds to Colleges, Universities, and Professional Schools.

MES at The Evergreen State College’s Presence on Crunchbase

No, MES at The Evergreen State College does not have a profile on Crunchbase.

MES at The Evergreen State College’s Presence on LinkedIn

Yes, MES at The Evergreen State College maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/mesevergreen.

Cybersecurity Incidents Involving MES at The Evergreen State College

As of January 25, 2026, Rankiteo reports that MES at The Evergreen State College has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

MES at The Evergreen State College has an estimated 15,203 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at MES at The Evergreen State College ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does MES at The Evergreen State College detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes (notification letters sent, credit monitoring offered), and remediation measures with offered 12 months of free experian identityworks credit monitoring and identity protection services, and communication strategy with notification letters mailed to affected individuals (2025-10-17); disclosure to washington attorney general (2025-10-17)..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: The Evergreen State College Data Breach (2025)

Description: The Evergreen State College experienced a data breach between May 21, 2025, and June 10, 2025, involving unauthorized access to a legacy file share system containing sensitive student information. The breach exposed personally identifiable information (PII) of several thousand students, including names, Social Security numbers, full dates of birth, and student ID numbers. Notification letters were mailed to affected individuals on October 17, 2025, and the incident was disclosed to the Washington Attorney General on the same date, reporting 7,727 Washington residents affected.

Date Detected: 2025-06-10

Date Publicly Disclosed: 2025-10-17

Type: Data Breach

Attack Vector: Unauthorized access to legacy file share system

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Legacy file share system.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach MES1302813102325

Data Compromised: Name, Social security number, Full date of birth, Student id number

Systems Affected: Legacy file share system

Brand Reputation Impact: Potential reputational damage due to exposure of sensitive student data

Legal Liabilities: Potential lawsuits and compensation claims for affected individuals

Identity Theft Risk: High (due to exposure of SSNs, full dates of birth, and student IDs)

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Student Records and .

Which entities were affected by each incident ?

Incident : Data Breach MES1302813102325

Entity Name: The Evergreen State College

Entity Type: Public Liberal Arts College

Industry: Education

Location: Olympia, Washington, USA

Customers Affected: 7,727 (Washington residents); several thousand (total students)

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach MES1302813102325

Incident Response Plan Activated: Yes (notification letters sent, credit monitoring offered)

Remediation Measures: Offered 12 months of free Experian IdentityWorks credit monitoring and identity protection services

Communication Strategy: Notification letters mailed to affected individuals (2025-10-17); disclosure to Washington Attorney General (2025-10-17)

What is the company's incident response plan?

Incident Response Plan: The company's incident response plan is described as Yes (notification letters sent, credit monitoring offered).

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach MES1302813102325

Type of Data Compromised: Personally identifiable information (pii), Student records

Number of Records Exposed: 7,727 (Washington residents); several thousand (total)

Sensitivity of Data: High (includes SSNs, full dates of birth, student IDs)

Data Exfiltration: Likely (unauthorized access to files)

Personally Identifiable Information: NameSocial Security numberFull date of birthStudent ID number

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Offered 12 months of free Experian IdentityWorks credit monitoring and identity protection services, .

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Breach MES1302813102325

Legal Actions: Potential lawsuits by affected individuals (investigation ongoing by Shamis & Gentile P.A.)

Regulatory Notifications: Washington Attorney General (disclosed 2025-10-17)

How does the company ensure compliance with regulatory requirements ?

Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through Potential lawsuits by affected individuals (investigation ongoing by Shamis & Gentile P.A.).

Lessons Learned and Recommendations

What recommendations were made to prevent future incidents ?

Incident : Data Breach MES1302813102325

Recommendations: Enroll in free credit monitoring (Experian IdentityWorks) offered by the college., Monitor financial statements for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel if affected.Enroll in free credit monitoring (Experian IdentityWorks) offered by the college., Monitor financial statements for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel if affected.Enroll in free credit monitoring (Experian IdentityWorks) offered by the college., Monitor financial statements for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel if affected.Enroll in free credit monitoring (Experian IdentityWorks) offered by the college., Monitor financial statements for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel if affected.Enroll in free credit monitoring (Experian IdentityWorks) offered by the college., Monitor financial statements for suspicious activity., Place a fraud alert on credit reports., Request free annual credit reports from major bureaus., Seek legal counsel if affected.

References

Where can I find more information about each incident ?

Incident : Data Breach MES1302813102325

Source: Shamis & Gentile P.A. Investigation Notice

Incident : Data Breach MES1302813102325

Source: The Evergreen State College Notification Letters

Date Accessed: 2025-10-17

Incident : Data Breach MES1302813102325

Source: Washington Attorney General Disclosure

Date Accessed: 2025-10-17

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Shamis & Gentile P.A. Investigation Notice, and Source: The Evergreen State College Notification LettersDate Accessed: 2025-10-17, and Source: Washington Attorney General DisclosureDate Accessed: 2025-10-17.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach MES1302813102325

Investigation Status: Ongoing (legal investigation by Shamis & Gentile P.A.; college response active)

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notification letters mailed to affected individuals (2025-10-17); disclosure to Washington Attorney General (2025-10-17).

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Breach MES1302813102325

Stakeholder Advisories: Notification Letters To Affected Individuals; Disclosure To Washington Attorney General.

Customer Advisories: Enroll in free credit monitoring (Experian IdentityWorks).Monitor accounts for suspicious activity.Consider fraud alerts and credit freezes.Seek legal assistance if needed.

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Notification Letters To Affected Individuals; Disclosure To Washington Attorney General, Enroll In Free Credit Monitoring (Experian Identityworks)., Monitor Accounts For Suspicious Activity., Consider Fraud Alerts And Credit Freezes., Seek Legal Assistance If Needed. and .

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach MES1302813102325

Entry Point: Legacy file share system

High Value Targets: Student Pii (Ssns, Dates Of Birth, Student Ids),

Data Sold on Dark Web: Student Pii (Ssns, Dates Of Birth, Student Ids),

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach MES1302813102325

Root Causes: Unauthorized Access To Legacy File Share System; Potential Lack Of Modern Security Controls,

Corrective Actions: Offered Credit Monitoring To Affected Individuals; Likely Reviewing Legacy System Security,

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Offered Credit Monitoring To Affected Individuals; Likely Reviewing Legacy System Security, .

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2025-06-10.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-10-17.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Name, Social Security number, Full date of birth, Student ID number and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Legacy file share system.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Full date of birth, Name, Social Security number and Student ID number.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 7.7K.

Regulatory Compliance

What was the most significant legal action taken for a regulatory violation ?

Most Significant Legal Action: The most significant legal action taken for a regulatory violation was Potential lawsuits by affected individuals (investigation ongoing by Shamis & Gentile P.A.).

Lessons Learned and Recommendations

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Seek legal counsel if affected., Place a fraud alert on credit reports., Enroll in free credit monitoring (Experian IdentityWorks) offered by the college., Monitor financial statements for suspicious activity. and Request free annual credit reports from major bureaus..

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Shamis & Gentile P.A. Investigation Notice, Washington Attorney General Disclosure and The Evergreen State College Notification Letters.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (legal investigation by Shamis & Gentile P.A.; college response active).

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Notification letters to affected individuals; disclosure to Washington Attorney General, .

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an Enroll in free credit monitoring (Experian IdentityWorks).Monitor accounts for suspicious activity.Consider fraud alerts and credit freezes.Seek legal assistance if needed.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an Legacy file share system.

cve

Latest Global CVEs (Not Company-Specific)

Description

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Description

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.

Description

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.

Description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Risk Information
cvss3
Base: 6.0
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
cvss4
Base: 6.0
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=mesevergreen' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge