CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2024-11071 - Cyberdigm DestinyECM Cross-Site Request Forgery (CSRF) and JSON Hijacking

CVE ID : CVE-2024-11071
Published : April 7, 2025, 6:15 a.m. | 3 hours, 3 minutes ago
Description : Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via forgery web page.* Due to product customization, version information may differ from the following version description. For further inquiries, please contact the vendor.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3338 - Codeprojects Online Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3338
Published : April 7, 2025, 6:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability classified as critical has been found in codeprojects Online Restaurant Management System 1.0. Affected is an unknown function of the file /admin/user_save.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3339 - Codeprojects Online Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3339
Published : April 7, 2025, 6:15 a.m. | 3 hours, 3 minutes ago
Description : A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user_update.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3340 - Codeprojects Online Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3340
Published : April 7, 2025, 7:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/combo_update.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3341 - Codeprojects Online Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3341
Published : April 7, 2025, 7:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3342 - Codeprojects Online Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3342
Published : April 7, 2025, 8:15 a.m. | 1 hour, 3 minutes ago
Description : A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3343 - Codeprojects Online Restaurant Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3343
Published : April 7, 2025, 8:15 a.m. | 1 hour, 3 minutes ago
Description : A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45552 - VivoLink Video Call RTCP Packet Information Disclosure

CVE ID : CVE-2024-45552
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45556 - Texas Instruments TCSR Linux Cryptographic Access Control Vulnerability

CVE ID : CVE-2024-45556
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45557 - Intel TME Memory Corruption Vulnerability

CVE ID : CVE-2024-45557
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-49848 - Qualcomm Snapdragon DSP IOCTL Memory Corruption Vulnerability

CVE ID : CVE-2024-49848
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21421 - Apache HTTP Server Buffer Overflow

CVE ID : CVE-2025-21421
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption while processing escape code in API.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21423 - Citrix Receiver Use-After-Free

CVE ID : CVE-2025-21423
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21425 - Citrix Systems HAB Process Memory Corruption Vulnerability

CVE ID : CVE-2025-21425
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption may occur due top improper access control in HAB process.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21428 - Aruba Wireless TSpec Memory Corruption Vulnerability

CVE ID : CVE-2025-21428
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21429 - Cisco Wireless STA Memory Corruption Vulnerability (Buffer Overflow)

CVE ID : CVE-2025-21429
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21430 - Cisco Wireless Router Denial of Service

CVE ID : CVE-2025-21430
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21431 - VMware Guest VM Information Disclosure

CVE ID : CVE-2025-21431
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Information disclosure may be there when a guest VM is connected.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21434 - Cisco Wireless LAN Controller Denial of Service Vulnerability

CVE ID : CVE-2025-21434
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21435 - Cisco ASA Internet Explorer Parsing Denial of Service

CVE ID : CVE-2025-21435
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Transient DOS may occur while parsing extended IE in beacon.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21436 - Adobe Flash Memory Corruption Vulnerability

CVE ID : CVE-2025-21436
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...