CVE tracker
311 subscribers
4.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-2782 - WatchGuard Terminal Services Agent Directory Permissions Escalation

CVE ID : CVE-2025-2782
Published : March 28, 2025, 11:15 p.m. | 2 hours, 44 minutes ago
Description : The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Terminal Services Agent: from 12.0 through 12.10.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-43186 - IBM InfoSphere Information Server Local File Disclosure

CVE ID : CVE-2024-43186
Published : March 29, 2025, 12:15 a.m. | 1 hour, 44 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-51477 - IBM InfoSphere Information Server Information Disclosure Vulnerability

CVE ID : CVE-2024-51477
Published : March 29, 2025, 12:15 a.m. | 1 hour, 44 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-7577 - IBM InfoSphere Information Server Credentials Disclosure Vulnerability

CVE ID : CVE-2024-7577
Published : March 29, 2025, 12:15 a.m. | 1 hour, 44 minutes ago
Description : IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31367 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-31367
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31368 - Apache HTTP Server Command Injection

CVE ID : CVE-2025-31368
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31369 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-31369
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31370 - Apache HTTP Server Denial of Service

CVE ID : CVE-2025-31370
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31371 - Apache HTTP Server Command Injection

CVE ID : CVE-2025-31371
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31372 - Cisco Webex Meeting Server Unvalidated Redirect

CVE ID : CVE-2025-31372
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31373 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-31373
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31374 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-31374
Published : March 29, 2025, 4:15 a.m. | 1 hour, 44 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1217 - Apache HTTP Server HTTP Response Header Parsing Vulnerability

CVE ID : CVE-2025-1217
Published : March 29, 2025, 6:15 a.m. | 3 hours, 43 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13557 - United Themes WordPress Shortcodes Arbitrary Execution Vulnerability

CVE ID : CVE-2024-13557
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2006 - "BBPress Inline Image Upload Arbitrary File Upload Vulnerability"

CVE ID : CVE-2025-2006
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This may be exploitable by unauthenticated attackers when the "Allow guest users without accounts to create topics and replies" setting is enabled.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2249 - "WordPress SoJ SoundSlides Arbitrary File Upload Vulnerability"

CVE ID : CVE-2025-2249
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2266 - WooCommerce Checkout Mestres do WP Privilege Escalation Vulnerability

CVE ID : CVE-2025-2266
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2803 - WordPress So-Called Air Quotes Plugin Shortcode Injection Vulnerability

CVE ID : CVE-2025-2803
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2840 - WordPress DAP to Autoresponders Email Syncing Sensitive Information Exposure

CVE ID : CVE-2025-2840
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-11180 - "ElementsKit Elementor Addons WordPress Stored Cross-Site Scripting Vulnerability"

CVE ID : CVE-2024-11180
Published : March 29, 2025, 8:15 a.m. | 1 hour, 44 minutes ago
Description : The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-55895 - IBM InfoSphere Information Server Information Disclosure Vulnerability

CVE ID : CVE-2024-55895
Published : March 29, 2025, 1:15 p.m. | 51 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...