CVE tracker
311 subscribers
4.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-1217 - Apache HTTP Server HTTP Response Header Parsing Vulnerability

CVE ID : CVE-2025-1217
Published : March 29, 2025, 6:15 a.m. | 3 hours, 43 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13557 - United Themes WordPress Shortcodes Arbitrary Execution Vulnerability

CVE ID : CVE-2024-13557
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2006 - "BBPress Inline Image Upload Arbitrary File Upload Vulnerability"

CVE ID : CVE-2025-2006
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This may be exploitable by unauthenticated attackers when the "Allow guest users without accounts to create topics and replies" setting is enabled.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2249 - "WordPress SoJ SoundSlides Arbitrary File Upload Vulnerability"

CVE ID : CVE-2025-2249
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2266 - WooCommerce Checkout Mestres do WP Privilege Escalation Vulnerability

CVE ID : CVE-2025-2266
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2803 - WordPress So-Called Air Quotes Plugin Shortcode Injection Vulnerability

CVE ID : CVE-2025-2803
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2840 - WordPress DAP to Autoresponders Email Syncing Sensitive Information Exposure

CVE ID : CVE-2025-2840
Published : March 29, 2025, 7:15 a.m. | 2 hours, 44 minutes ago
Description : The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-11180 - "ElementsKit Elementor Addons WordPress Stored Cross-Site Scripting Vulnerability"

CVE ID : CVE-2024-11180
Published : March 29, 2025, 8:15 a.m. | 1 hour, 44 minutes ago
Description : The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-55895 - IBM InfoSphere Information Server Information Disclosure Vulnerability

CVE ID : CVE-2024-55895
Published : March 29, 2025, 1:15 p.m. | 51 minutes ago
Description : IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1219 - Apache HTTP Server PHP DOM XML Charset Bypass

CVE ID : CVE-2025-1219
Published : March 30, 2025, 6:15 a.m. | 1 hour, 59 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1734 - Apache HTTP Server Header Injection Vulnerability

CVE ID : CVE-2025-1734
Published : March 30, 2025, 6:15 a.m. | 1 hour, 59 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1736 - Apache PHP Header Injection

CVE ID : CVE-2025-1736
Published : March 30, 2025, 6:15 a.m. | 1 hour, 59 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1861 - Apache HTTP Server URL Truncation Vulnerability

CVE ID : CVE-2025-1861
Published : March 30, 2025, 6:15 a.m. | 1 hour, 59 minutes ago
Description : In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2951 - Bluestar Micro Mall SQL Injection Vulnerability

CVE ID : CVE-2025-2951
Published : March 30, 2025, 12:15 p.m. | 35 minutes ago
Description : A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2952 - Bluestar Micro Mall Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-2952
Published : March 30, 2025, 3:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2953 - PyTorch Denial of Service (DoS) in torch.mkldnn_max_pool2d

CVE ID : CVE-2025-2953
Published : March 30, 2025, 4:15 p.m. | 2 hours, 58 minutes ago
Description : A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2954 - Mannaandpoem OpenManus File Handler Improper Access Control Vulnerability

CVE ID : CVE-2025-2954
Published : March 30, 2025, 5:15 p.m. | 1 hour, 58 minutes ago
Description : A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2955 - TOTOLINK A3000RU IBMS Configuration File Handler Improper Access Control Remote Vulnerability

CVE ID : CVE-2025-2955
Published : March 30, 2025, 6:15 p.m. | 58 minutes ago
Description : A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of the component IBMS Configuration File Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2956 - TRENDnet Lighttpd HTTP Request Handler Null Pointer Dereference

CVE ID : CVE-2025-2956
Published : March 30, 2025, 6:15 p.m. | 58 minutes ago
Description : A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2957 - TRENDnet TEW-411BRP+ HTTP Request Handler Null Pointer Dereference Vulnerability

CVE ID : CVE-2025-2957
Published : March 30, 2025, 7:15 p.m. | 3 hours, 7 minutes ago
Description : A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2958 - TRENDnet TEW-818DRU HTTP Request Handler Denial of Service Vulnerability

CVE ID : CVE-2025-2958
Published : March 30, 2025, 8:15 p.m. | 2 hours, 7 minutes ago
Description : A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...