CVE tracker
367 subscribers
5.02K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-30620 - Coderscom WP Odoo Form Integrator CSRF Stored XSS

CVE ID : CVE-2025-30620
Published : March 24, 2025, 2:15 p.m. | 3 hours, 42 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in coderscom WP Odoo Form Integrator allows Stored XSS. This issue affects WP Odoo Form Integrator: from n/a through 1.1.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30621 - Kornelly Translator CSRF Stored XSS

CVE ID : CVE-2025-30621
Published : March 24, 2025, 2:15 p.m. | 3 hours, 42 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator allows Stored XSS. This issue affects Translator: from n/a through 0.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30623 - wA11y Web Accessibility Toolbox Cross-site Scripting

CVE ID : CVE-2025-30623
Published : March 24, 2025, 2:15 p.m. | 3 hours, 42 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry wA11y – The Web Accessibility Toolbox allows Stored XSS. This issue affects wA11y – The Web Accessibility Toolbox: from n/a through 1.0.3.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-55279 - Uguu XSS Vulnerability

CVE ID : CVE-2024-55279
Published : March 24, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1558 - Mattermost Mobile Apps GIF Image Rendering Vulnerability

CVE ID : CVE-2025-1558
Published : March 24, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2326 - Apache HTTP Server Remote Code Execution Vulnerability

CVE ID : CVE-2025-2326
Published : March 24, 2025, 3:15 p.m. | 2 hours, 42 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-26091 - FortiMail Cryptographically Weak PRNG Authentication Token Vulnerability

CVE ID : CVE-2021-26091
Published : March 24, 2025, 4:15 p.m. | 1 hour, 42 minutes ago
Description : A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-26105 - FortiSandbox Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2021-26105
Published : March 24, 2025, 4:15 p.m. | 1 hour, 42 minutes ago
Description : A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-25610 - Fortinet FortiOS and FortiProxy Buffer Underwrite Remote Code Execution

CVE ID : CVE-2023-25610
Published : March 24, 2025, 4:15 p.m. | 1 hour, 42 minutes ago
Description : A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-9103 - Forcepoint Email Security Stored XSS in Blocked Messages Module

CVE ID : CVE-2024-9103
Published : March 24, 2025, 4:15 p.m. | 1 hour, 42 minutes ago
Description : Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email Security through 8.5.5.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0256 - HCL DevOps Deploy / HCL Launch Authentication Bypass Information Disclosure Vulnerability

CVE ID : CVE-2025-0256
Published : March 24, 2025, 4:15 p.m. | 1 hour, 42 minutes ago
Description : HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23204 - API Platform Core GraphQL Security Check Bypass

CVE ID : CVE-2025-23204
Published : March 24, 2025, 4:15 p.m. | 1 hour, 41 minutes ago
Description : API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. Version 3.3.15 contains a patch for the issue.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29294 - H3C Router Code Execution Vulnerability

CVE ID : CVE-2025-29294
Published : March 24, 2025, 4:15 p.m. | 1 hour, 41 minutes ago
Description : Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2705 - Digiwin ERP Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-2705
Published : March 24, 2025, 4:15 p.m. | 1 hour, 41 minutes ago
Description : A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0255 - HCL DevOps Deploy/HCL Launch Command Injection Vulnerability

CVE ID : CVE-2025-0255
Published : March 24, 2025, 5:15 p.m. | 42 minutes ago
Description : HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29778 - Kyverno Keyless Certificate Verification Bypass

CVE ID : CVE-2025-29778
Published : March 24, 2025, 5:15 p.m. | 42 minutes ago
Description : Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to deploy kubernetes resources with the artifacts that were signed by unexpected certificate. Deploying these unauthorized kubernetes resources can lead to full compromise of kubernetes cluster. Version 1.14.0-alpha.1 contains a patch for the issue.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30112 - "70mai Dash Cam 1S Authorization Bypass"

CVE ID : CVE-2025-30112
Published : March 24, 2025, 5:15 p.m. | 42 minutes ago
Description : On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30205 - Kanidim-Provision Admin Credential Leakage Vulnerability

CVE ID : CVE-2025-30205
Published : March 24, 2025, 5:15 p.m. | 42 minutes ago
Description : kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm patches provided by kandim-provision will cause the provisioned admin credentials to be leaked to the system log. This only impacts users which both use the provided patches and provision their `admin` or `idm_admin` account credentials this way. No other credentials are affected. Users should recompile kanidm with the newest patchset from tag `v1.2.0` or higher. As a workaround, the user can set the log level `KANIDM_LOG_LEVEL` to any level higher than `info`, for example `warn`.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30208 - Vite File Access Bypass Vulnerability

CVE ID : CVE-2025-30208
Published : March 24, 2025, 5:15 p.m. | 42 minutes ago
Description : Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22223 - Spring Security Authorization Bypass in Method Security Annotations

CVE ID : CVE-2025-22223
Published : March 24, 2025, 6:15 p.m. | 3 hours, 42 minutes ago
Description : Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass.  You are not affected if you are not using @EnableMethodSecurity, or you do not have method security annotations on parameterized types or methods, or all method security annotations are attached to target methods
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2706 - Digiwin ERP Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-2706
Published : March 24, 2025, 7:15 p.m. | 2 hours, 42 minutes ago
Description : A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...