CVE tracker
369 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-2637 - JIZHICMS Remote Improper Authorization Vulnerability

CVE ID : CVE-2025-2637
Published : March 23, 2025, 12:15 a.m. | 1 hour, 41 minutes ago
Description : A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jifen leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2638 - JIZHICMS Article Handler Remote Authorization Bypass

CVE ID : CVE-2025-2638
Published : March 23, 2025, 2:15 a.m. | 3 hours, 41 minutes ago
Description : A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html of the component Article Handler. The manipulation of the argument ishot with the input 1 leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2639 - JIZHICMS Remote Unauthorized Access Vulnerability

CVE ID : CVE-2025-2639
Published : March 23, 2025, 3:15 a.m. | 2 hours, 41 minutes ago
Description : A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2640 - PHPGurukul Doctor Appointment Management System SQL Injection

CVE ID : CVE-2025-2640
Published : March 23, 2025, 4:15 a.m. | 1 hour, 41 minutes ago
Description : A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /doctor/appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2641 - PHPGurukul Art Gallery Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2641
Published : March 23, 2025, 5:15 a.m. | 41 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-artist-detail.php?editid=1. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0718 - WordPress Nested Pages Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-0718
Published : March 23, 2025, 6:15 a.m. | 3 hours, 41 minutes ago
Description : The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1446 - "Pods SQL Injection Vulnerability"

CVE ID : CVE-2025-1446
Published : March 23, 2025, 6:15 a.m. | 3 hours, 41 minutes ago
Description : The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2642 - PHPGurukul Art Gallery Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2642
Published : March 23, 2025, 7:15 a.m. | 2 hours, 41 minutes ago
Description : A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/edit-art-product-detail.php?editid=2. The manipulation of the argument editide/sprice/description leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2643 - PHPGurukul Art Gallery Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2643
Published : March 23, 2025, 8:15 a.m. | 1 hour, 41 minutes ago
Description : A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-art-type-detail.php?editid=1. The manipulation of the argument arttype leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2644 - PHPGurukul Art Gallery Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2644
Published : March 23, 2025, 8:15 a.m. | 1 hour, 41 minutes ago
Description : A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add-art-product.php. The manipulation of the argument arttype leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2645 - PHPGurukul Art Gallery Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-2645
Published : March 23, 2025, 9:15 a.m. | 41 minutes ago
Description : A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /product.php. The manipulation of the argument artname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2646 - PHPGurukul Art Gallery Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2646
Published : March 23, 2025, 10:15 a.m. | 3 hours, 41 minutes ago
Description : A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2647 - "PHPGurukul Art Gallery Management System SQL Injection"

CVE ID : CVE-2025-2647
Published : March 23, 2025, 11:15 a.m. | 2 hours, 41 minutes ago
Description : A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search.php. The manipulation of the argument Search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2648 - PHPGurukul Art Gallery Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2648
Published : March 23, 2025, 12:15 p.m. | 1 hour, 41 minutes ago
Description : A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/view-enquiry-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2649 - PHPGurukul Doctor Appointment Management System SQL Injection Vulnerability

CVE ID : CVE-2025-2649
Published : March 23, 2025, 12:15 p.m. | 1 hour, 41 minutes ago
Description : A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2650 - PHPGurukul Medical Card Generation System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-2650
Published : March 23, 2025, 2:15 p.m. | 3 hours, 42 minutes ago
Description : A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0927 - Linux Kernel HFS+ Heap Overflow Vulnerability

CVE ID : CVE-2025-0927
Published : March 23, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27553 - Apache Commons VFS Descendant File Object Path Traversal Vulnerability

CVE ID : CVE-2025-27553
Published : March 23, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2651 - SourceCodester Online Eyewear Shop Remote Directory Traversal

CVE ID : CVE-2025-2651
Published : March 23, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2652 - SourceCodester Employee and Visitor Gate Pass Logging System Information Disclosure

CVE ID : CVE-2025-2652
Published : March 23, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2691 - Nossrf SSRF

CVE ID : CVE-2025-2691
Published : March 23, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...