CVE tracker
369 subscribers
5.06K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-29218 - Tenda W18E Stack Overflow Vulnerability

CVE ID : CVE-2025-29218
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29980 - eTRAKiT.net SQL Injection Vulnerability

CVE ID : CVE-2025-29980
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no longer supported, and users are recommended to migrate to the latest version of CentralSquare Community Development.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2557 - "Audi UTR Dashcam 2.0 Command API Local Network Access Control Vulnerability"

CVE ID : CVE-2025-2557
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of the component Command API. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. Upgrading to version 2.89 and 2.90 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about these issues and acted very professional. Version 2.89 is fixing this issue for new customers and 2.90 is going to fix it for existing customers.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30160 - Redlib DEFLATE Decompression Bomb Denial-of-Service Vulnerability

CVE ID : CVE-2025-30160
Published : March 20, 2025, 7:15 p.m. | 2 hours, 35 minutes ago
Description : Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26852 - DESCOR InfoCad SQL Injection Vulnerability

CVE ID : CVE-2025-26852
Published : March 20, 2025, 8:15 p.m. | 1 hour, 35 minutes ago
Description : DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26853 - DESCOR InfoCAD Authentication Bypass Vulnerability

CVE ID : CVE-2025-26853
Published : March 20, 2025, 8:15 p.m. | 1 hour, 35 minutes ago
Description : DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25758 - KukuFM Android Backup Data Exposure

CVE ID : CVE-2025-25758
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2538 - Esri ArcGIS Enterprise Portal Password Recovery Exploitation Vulnerability

CVE ID : CVE-2025-2538
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : A specific type of ArcGIS Enterprise deployment, is vulnerable to a Password Recovery Exploitation vulnerability in Portal, that could allow an attacker to reset the password on the built in admin account.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2574 - Xpdf Out-of-bounds Array Write Vulnerability

CVE ID : CVE-2025-2574
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30334 - OpenBSD wg(4) Kernel Crash Vulnerability

CVE ID : CVE-2025-30334
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2198 - CVE-2020-13143 Apache Struts Command Injection

CVE ID : CVE-2025-2198
Published : March 20, 2025, 11:15 p.m. | 2 hours, 37 minutes ago
Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-44199 - Apple macOS out-of-bounds read vulnerability

CVE ID : CVE-2024-44199
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected system termination or read kernel memory.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-44305 - Apple macOS Root Privilege Escalation

CVE ID : CVE-2024-44305
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54551 - Apple Safari Denial-of-Service Vulnerability

CVE ID : CVE-2024-54551
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.6, tvOS 17.6, Safari 17.6, macOS Sonoma 14.6, visionOS 1.3, iOS 17.6 and iPadOS 17.6. Processing web content may lead to a denial-of-service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54564 - VisionOS AirDrop Quarantine Flag Bypass

CVE ID : CVE-2024-54564
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-28207 - Apple Plug-in App Permission Inheritance Vulnerability

CVE ID : CVE-2023-28207
Published : March 21, 2025, 1:15 a.m. | 38 minutes ago
Description : The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29807 - Microsoft Dataverse Remote Code Execution

CVE ID : CVE-2025-29807
Published : March 21, 2025, 1:15 a.m. | 37 minutes ago
Description : Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29814 - Microsoft Partner Center Privilege Escalation Vulnerability

CVE ID : CVE-2025-29814
Published : March 21, 2025, 1:15 a.m. | 37 minutes ago
Description : Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2585 - EBM Maintenance Center SQL Injection Vulnerability

CVE ID : CVE-2025-2585
Published : March 21, 2025, 2:15 a.m. | 3 hours, 40 minutes ago
Description : EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-50053 - Zohocorp ManageEngine ServiceDesk Plus Stored Cross-Site Scripting

CVE ID : CVE-2024-50053
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30342 - OpenSlides Cross-Site Scripting (XSS)

CVE ID : CVE-2025-30342
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element, it is properly encoded when reflected; however, adding attributes to links is possible, which allows the injection of JavaScript via the onmouseover attribute and others. When a user moves the mouse over such a prepared link, JavaScript is executed in that user's session.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...