CVE tracker
335 subscribers
4.63K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-20120 - Cisco EPNM and Prime Infrastructure Stored XSS Vulnerability

CVE ID : CVE-2025-20120
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-20139 - Cisco Enterprise Chat and Email Remote Denial of Service (DoS)

CVE ID : CVE-2025-20139
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-20203 - Cisco EPNM and Prime Infrastructure Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-20203
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials. {{value}} ["%7b%7bvalue%7d%7d"])}]]
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-20212 - Cisco AnyConnect VPN Denial of Service Vulnerability

CVE ID : CVE-2025-20212
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user credentials on the affected device. This vulnerability exists because a variable is not initialized when an SSL VPN session is established. An attacker could exploit this vulnerability by supplying crafted attributes while establishing an SSL VPN session with an affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to restart, resulting in the failure of the established SSL VPN sessions and forcing remote users to initiate a new VPN connection and reauthenticate. A sustained attack could prevent new SSL VPN connections from being established. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers without manual intervention.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31282 - Trend Vision One User Account Privilege Escalation

CVE ID : CVE-2025-31282
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31283 - Trend Vision One Escalation of Privilege Vulnerability

CVE ID : CVE-2025-31283
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31284 - Trend Vision One Status Privilege Escalation Vulnerability

CVE ID : CVE-2025-31284
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31285 - Trend Vision One Role Name Privilege Escalation Vulnerability

CVE ID : CVE-2025-31285
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31286 - Trend Vision One HTML Injection Vulnerability

CVE ID : CVE-2025-31286
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-37917 - Pexip Infinity Denial of Service

CVE ID : CVE-2024-37917
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-38392 - Pexip Infinity Connect Remote Code Execution

CVE ID : CVE-2024-38392
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22923 - OS4ED openSIS File Deletion Directory Traversal

CVE ID : CVE-2025-22923
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22924 - OS4ED openSIS SQL Injection Vulnerability

CVE ID : CVE-2025-22924
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22925 - OS4ED openSIS SQL Injection

CVE ID : CVE-2025-22925
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29062 - BL-AC2100 Remote Code Execution Vulnerability

CVE ID : CVE-2025-29062
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29063 - BL-AC2100 Router Code Execution Vulnerability

CVE ID : CVE-2025-29063
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29085 - Vipshop Saturn SQL Injection Vulnerability

CVE ID : CVE-2025-29085
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29719 - SourceCodester rems Employee Management System Cross Site Scripting (XSS)

CVE ID : CVE-2025-29719
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2704 - OpenVPN TLS-crypt-v2 Denial of Service

CVE ID : CVE-2025-2704
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30080 - Pexip Infinity Denial of Service

CVE ID : CVE-2025-30080
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3118 - SourceCodester Online Tutor Portal SQL Injection

CVE ID : CVE-2025-3118
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...