CVE tracker
369 subscribers
5.06K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-26853 - DESCOR InfoCAD Authentication Bypass Vulnerability

CVE ID : CVE-2025-26853
Published : March 20, 2025, 8:15 p.m. | 1 hour, 35 minutes ago
Description : DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25758 - KukuFM Android Backup Data Exposure

CVE ID : CVE-2025-25758
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2538 - Esri ArcGIS Enterprise Portal Password Recovery Exploitation Vulnerability

CVE ID : CVE-2025-2538
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : A specific type of ArcGIS Enterprise deployment, is vulnerable to a Password Recovery Exploitation vulnerability in Portal, that could allow an attacker to reset the password on the built in admin account.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2574 - Xpdf Out-of-bounds Array Write Vulnerability

CVE ID : CVE-2025-2574
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30334 - OpenBSD wg(4) Kernel Crash Vulnerability

CVE ID : CVE-2025-30334
Published : March 20, 2025, 9:15 p.m. | 35 minutes ago
Description : In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2198 - CVE-2020-13143 Apache Struts Command Injection

CVE ID : CVE-2025-2198
Published : March 20, 2025, 11:15 p.m. | 2 hours, 37 minutes ago
Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-44199 - Apple macOS out-of-bounds read vulnerability

CVE ID : CVE-2024-44199
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected system termination or read kernel memory.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-44305 - Apple macOS Root Privilege Escalation

CVE ID : CVE-2024-44305
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54551 - Apple Safari Denial-of-Service Vulnerability

CVE ID : CVE-2024-54551
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.6, tvOS 17.6, Safari 17.6, macOS Sonoma 14.6, visionOS 1.3, iOS 17.6 and iPadOS 17.6. Processing web content may lead to a denial-of-service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54564 - VisionOS AirDrop Quarantine Flag Bypass

CVE ID : CVE-2024-54564
Published : March 21, 2025, 12:15 a.m. | 1 hour, 37 minutes ago
Description : This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-28207 - Apple Plug-in App Permission Inheritance Vulnerability

CVE ID : CVE-2023-28207
Published : March 21, 2025, 1:15 a.m. | 38 minutes ago
Description : The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29807 - Microsoft Dataverse Remote Code Execution

CVE ID : CVE-2025-29807
Published : March 21, 2025, 1:15 a.m. | 37 minutes ago
Description : Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29814 - Microsoft Partner Center Privilege Escalation Vulnerability

CVE ID : CVE-2025-29814
Published : March 21, 2025, 1:15 a.m. | 37 minutes ago
Description : Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2585 - EBM Maintenance Center SQL Injection Vulnerability

CVE ID : CVE-2025-2585
Published : March 21, 2025, 2:15 a.m. | 3 hours, 40 minutes ago
Description : EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-50053 - Zohocorp ManageEngine ServiceDesk Plus Stored Cross-Site Scripting

CVE ID : CVE-2024-50053
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30342 - OpenSlides Cross-Site Scripting (XSS)

CVE ID : CVE-2025-30342
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element, it is properly encoded when reflected; however, adding attributes to links is possible, which allows the injection of JavaScript via the onmouseover attribute and others. When a user moves the mouse over such a prepared link, JavaScript is executed in that user's session.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30343 - OpenSlides Directory Traversal Vulnerability

CVE ID : CVE-2025-30343
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory.
Severity: 3.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30344 - OpenSlides Timing-Based Authentication Bypass

CVE ID : CVE-2025-30344
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30345 - OpenSlides Cross-Site Scripting (XSS)

CVE ID : CVE-2025-30345
Published : March 21, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded properly, but not when deleting chats or deleting messages in these chats. This potentially allows attackers to interfere with the layout of the rendered website, but it is unlikely that victims would click on deleted chats or deleted messages.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13903 - QuickJS Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2024-13903
Published : March 21, 2025, 7:15 a.m. | 2 hours, 40 minutes ago
Description : A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c of the component qjs. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. Upgrading to version 0.9.0 is able to address this issue. The patch is named 99c02eb45170775a9a679c32b45dd4000ea67aff. It is recommended to upgrade the affected component.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2582 - SimpleMachines SMF Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2582
Published : March 21, 2025, 7:15 a.m. | 2 hours, 39 minutes ago
Description : A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...