CVE tracker
335 subscribers
4.62K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2024-37917 - Pexip Infinity Denial of Service

CVE ID : CVE-2024-37917
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-38392 - Pexip Infinity Connect Remote Code Execution

CVE ID : CVE-2024-38392
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22923 - OS4ED openSIS File Deletion Directory Traversal

CVE ID : CVE-2025-22923
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22924 - OS4ED openSIS SQL Injection Vulnerability

CVE ID : CVE-2025-22924
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22925 - OS4ED openSIS SQL Injection

CVE ID : CVE-2025-22925
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29062 - BL-AC2100 Remote Code Execution Vulnerability

CVE ID : CVE-2025-29062
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29063 - BL-AC2100 Router Code Execution Vulnerability

CVE ID : CVE-2025-29063
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29085 - Vipshop Saturn SQL Injection Vulnerability

CVE ID : CVE-2025-29085
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29719 - SourceCodester rems Employee Management System Cross Site Scripting (XSS)

CVE ID : CVE-2025-29719
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2704 - OpenVPN TLS-crypt-v2 Denial of Service

CVE ID : CVE-2025-2704
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30080 - Pexip Infinity Denial of Service

CVE ID : CVE-2025-30080
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3118 - SourceCodester Online Tutor Portal SQL Injection

CVE ID : CVE-2025-3118
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0257 - HCL DevOps Deploy/HCL Launch Agent Relay Authentication Bypass Vulnerability

CVE ID : CVE-2025-0257
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27608 - Arduino IDE Theia Framework Electron Self Cross-Site Scripting (XSS)

CVE ID : CVE-2025-27608
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Preferences -> Settings section of the Arduino IDE interface. In the vulnerable versions, any values entered in this field are directly displayed to the user through a notification tooltip object, without a proper output encoding routine, due to the underlying ElectronJS engine interpretation. This vulnerability exposes the input parameter to Self-XSS attacks, which may lead to security risks depending on where the malicious payload is injected. This vulnerability is fixed in 2.3.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30218 - Next.js Cross-Origin Request Exposure

CVE ID : CVE-2025-30218
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send the x-middleware-subrequest-id to that third party. This vulnerability is fixed in 12.3.6, 13.5.10, 14.2.26, and 15.2.4.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31477 - Tauri Shell Plugin Remote Code Execution Vulnerability

CVE ID : CVE-2025-31477
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be restricted to a reasonable number of protocols like https or mailto by default. This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like file://, smb://, or nfs:// and others to be opened by the system registered protocol handler. By passing untrusted user input to the open endpoint these potentially dangerous protocols can be abused to gain remote code execution on the system. This either requires direct exposure of the endpoint to application users or code execution in the frontend of a Tauri application. This vulnerability is fixed in 2.2.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31479 - GitHub Get-Workflow-Version-Action Token Truncation Vulnerability

CVE ID : CVE-2025-31479
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the GITHUB_TOKEN. If the full token is included in the exception output, GitHub will automatically redact the secret from the GitHub Actions logs. However, the token may be truncated—causing part of the GITHUB_TOKEN to be displayed in plaintext in the GitHub Actions logs. Anyone with read access to the GitHub repository can view GitHub Actions logs. For public repositories, anyone can view the GitHub Actions logs. The opportunity to exploit this vulnerability is limited—the GITHUB_TOKEN is automatically revoked when the job completes. However, there is an opportunity for an attack in the time between the GITHUB_TOKEN being displayed in the logs and the completion of the job. Users using the github-token input are impacted. This vulnerability is fixed in 1.0.1.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31484 - Conda-Forge Azure CF-Staging Token Exposure

CVE ID : CVE-2025-31484
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for Azure's cf-staging access. This bug meant that any feedstock maintainer could upload a package to the conda-forge channel, bypassing our feedstock-token + upload process. The security logs on anaconda.org were check for any packages that were not copied from the cf-staging to the conda-forge channel and none were found.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3119 - SourceCodester Online Tutor Portal SQL Injection Vulnerability

CVE ID : CVE-2025-3119
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3120 - "SourceCodester Apartment Visitors Management System SQL Injection Vulnerability"

CVE ID : CVE-2025-3120
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument apartmentno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3121 - PyTorch Memory Corruption (Local Access)

CVE ID : CVE-2025-3121
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...