CVE tracker
369 subscribers
5.06K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-29923 - Redis Go Client Out-of-Order Response Vulnerability

CVE ID : CVE-2025-29923
Published : March 20, 2025, 6:15 p.m. | 40 minutes ago
Description : go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when `CLIENT SETINFO` times out during connection establishment. This can happen when the client is configured to transmit its identity, there are network connectivity issues, or the client was configured with aggressive timeouts. The problem occurs for multiple use cases. For sticky connections, you receive persistent out-of-order responses for the lifetime of the connection. All commands in the pipeline receive incorrect responses. When used with the default ConnPool once a connection is returned after use with ConnPool#Put the read buffer will be checked and the connection will be marked as bad due to the unread data. This means that at most one out-of-order response before the connection is discarded. This issue is fixed in 9.5.5, 9.6.3, and 9.7.3. You can prevent the vulnerability by setting the flag DisableIndentity to true when constructing the client instance.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2553 - D-Link DIR-618 and DIR-605L Local File Inclusion Vulnerability

CVE ID : CVE-2025-2553
Published : March 20, 2025, 6:15 p.m. | 40 minutes ago
Description : A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects some unknown processing of the file /goform/formVirtualServ. The manipulation leads to improper access controls. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2555 - Audi Universal Traffic Recorder App FTP Credentials Hard-Coded Password Vulnerability

CVE ID : CVE-2025-2555
Published : March 20, 2025, 6:15 p.m. | 40 minutes ago
Description : A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unknown function of the component FTP Credentials. The manipulation leads to use of hard-coded password. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.89 and 2.90 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about these issues and acted very professional. Version 2.89 is fixing this issue for new customers and 2.90 is going to fix it for existing customers.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2556 - "Audi UTR Dashcam 2.0 Hard-Coded Credentials Vulnerability"

CVE ID : CVE-2025-2556
Published : March 20, 2025, 6:15 p.m. | 40 minutes ago
Description : A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknown functionality of the component Video Stream Handler. The manipulation leads to hard-coded credentials. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. Upgrading to version 2.89 and 2.90 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about these issues and acted very professional. Version 2.89 is fixing this issue for new customers and 2.90 is going to fix it for existing customers.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29217 - Tenda W18E Stack Overflow Denial of Service Vulnerability

CVE ID : CVE-2025-29217
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29218 - Tenda W18E Stack Overflow Vulnerability

CVE ID : CVE-2025-29218
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29980 - eTRAKiT.net SQL Injection Vulnerability

CVE ID : CVE-2025-29980
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no longer supported, and users are recommended to migrate to the latest version of CentralSquare Community Development.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2557 - "Audi UTR Dashcam 2.0 Command API Local Network Access Control Vulnerability"

CVE ID : CVE-2025-2557
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of the component Command API. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. Upgrading to version 2.89 and 2.90 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about these issues and acted very professional. Version 2.89 is fixing this issue for new customers and 2.90 is going to fix it for existing customers.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30160 - Redlib DEFLATE Decompression Bomb Denial-of-Service Vulnerability

CVE ID : CVE-2025-30160
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26852 - DESCOR InfoCad SQL Injection Vulnerability

CVE ID : CVE-2025-26852
Published : March 20, 2025, 8:15 p.m. | 1 hour, 35 minutes ago
Description : DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26853 - DESCOR InfoCAD Authentication Bypass Vulnerability

CVE ID : CVE-2025-26853
Published : March 20, 2025, 8:15 p.m. | 1 hour, 35 minutes ago
Description : DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25758 - KukuFM Android Backup Data Exposure

CVE ID : CVE-2025-25758
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2538 - Esri ArcGIS Enterprise Portal Password Recovery Exploitation Vulnerability

CVE ID : CVE-2025-2538
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : A specific type of ArcGIS Enterprise deployment, is vulnerable to a Password Recovery Exploitation vulnerability in Portal, that could allow an attacker to reset the password on the built in admin account.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2574 - Xpdf Out-of-bounds Array Write Vulnerability

CVE ID : CVE-2025-2574
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30334 - OpenBSD wg(4) Kernel Crash Vulnerability

CVE ID : CVE-2025-30334
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2198 - CVE-2020-13143 Apache Struts Command Injection

CVE ID : CVE-2025-2198
Published : March 20, 2025, 11:15 p.m. | 2 hours, 37 minutes ago
Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-44199 - Apple macOS out-of-bounds read vulnerability

CVE ID : CVE-2024-44199
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected system termination or read kernel memory.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-44305 - Apple macOS Root Privilege Escalation

CVE ID : CVE-2024-44305
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54551 - Apple Safari Denial-of-Service Vulnerability

CVE ID : CVE-2024-54551
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.6, tvOS 17.6, Safari 17.6, macOS Sonoma 14.6, visionOS 1.3, iOS 17.6 and iPadOS 17.6. Processing web content may lead to a denial-of-service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54564 - VisionOS AirDrop Quarantine Flag Bypass

CVE ID : CVE-2024-54564
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-28207 - Apple Plug-in App Permission Inheritance Vulnerability

CVE ID : CVE-2023-28207
Published : March 21, 2025, 1:15 a.m. | 38 minutes ago
Description : The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...