CVE tracker
311 subscribers
4.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-2975 - GFI KerioConnect Cross Site Scripting Vulnerability

CVE ID : CVE-2025-2975
Published : March 31, 2025, 4:15 a.m. | 2 hours, 11 minutes ago
Description : A vulnerability was found in GFI KerioConnect 10.0.6 and classified as problematic. This issue affects some unknown processing of the file Settings/Email/Signature/EditHtmlSource of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3011 - PiExtract SOOP-CLM SQL Injection Vulnerability

CVE ID : CVE-2025-3011
Published : March 31, 2025, 4:15 a.m. | 2 hours, 11 minutes ago
Description : SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3013 - NightWolf Penetration Testing Customer Portal IDOR

CVE ID : CVE-2025-3013
Published : March 31, 2025, 4:15 a.m. | 2 hours, 11 minutes ago
Description : Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3014 - NightWolf Penetration Testing Tracking IDOR

CVE ID : CVE-2025-3014
Published : March 31, 2025, 4:15 a.m. | 2 hours, 11 minutes ago
Description : Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipulating request parameters or object references.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24517 - CHOCO TEI WATCHER mini Authentication Bypass Vulnerability

CVE ID : CVE-2025-24517
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : Use of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a remote attacker may obtain the product login password without authentication.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24852 - CHOCO TEI WATCHER mini Password Disclosure Vulnerability

CVE ID : CVE-2025-24852
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can access the microSD card used on the product may obtain the product login password.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25211 - CHOCO TEI WATCHER mini Weak Password Authentication Bypass

CVE ID : CVE-2025-25211
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26689 - Choco Tei Watcher Mini HTTP Forced Browsing Vulnerability

CVE ID : CVE-2025-26689
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2976 - GFI KerioConnect Cross Site Scripting Vulnerability

CVE ID : CVE-2025-2976
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown function of the component File Upload. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2977 - GFI KerioConnect Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2977
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : A vulnerability was found in GFI KerioConnect 10.0.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31103 - "a-blog CMS File Deserialization Vulnerability"

CVE ID : CVE-2025-31103
Published : March 31, 2025, 5:15 a.m. | 1 hour, 11 minutes ago
Description : Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0613 - "10Web Photo Gallery WordPress Plugin Stored XSS Vulnerability"

CVE ID : CVE-2025-0613
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2978 - "WCMS Unrestricted File Upload Vulnerability"

CVE ID : CVE-2025-2978
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?articleadmin/upload/?&CKEditor=container&CKEditorFuncNum=1 of the component Article Publishing Page. The manipulation of the argument Upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2979 - "WCMS Cross-Site Scripting Vulnerability in Registration Component"

CVE ID : CVE-2025-2979
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php?anonymous/setregister of the component Registration. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 2.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30835 - Bastien Ho Accounting for WooCommerce PHP Remote File Inclusion

CVE ID : CVE-2025-30835
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Accounting for WooCommerce allows PHP Local File Inclusion. This issue affects Accounting for WooCommerce: from n/a through 1.6.8.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30855 - WPQuads Ads Missing Authorization Vulnerability

CVE ID : CVE-2025-30855
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30987 - JetBlocks For Elementor Cross-site Scripting (XSS)

CVE ID : CVE-2025-30987
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetBlocks For Elementor allows Stored XSS. This issue affects JetBlocks For Elementor: from n/a through 1.3.16.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31016 - JetWooBuilder PHP Remote File Inclusion Vulnerability

CVE ID : CVE-2025-31016
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound JetWooBuilder allows PHP Local File Inclusion. This issue affects JetWooBuilder: from n/a through 2.1.18.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31043 - JetSearch Cross-site Scripting

CVE ID : CVE-2025-31043
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetSearch allows DOM-Based XSS. This issue affects JetSearch: from n/a through 3.5.7.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31387 - InstaWP InstaWP Connect PHP Remote File Inclusion Vulnerability

CVE ID : CVE-2025-31387
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect allows PHP Local File Inclusion. This issue affects InstaWP Connect: from n/a through 0.1.0.82.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31412 - JetProductGallery Cross-site Scripting (XSS)

CVE ID : CVE-2025-31412
Published : March 31, 2025, 6:15 a.m. | 4 hours, 11 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetProductGallery allows DOM-Based XSS. This issue affects JetProductGallery: from n/a through 2.1.22.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...