CVE tracker
369 subscribers
5.06K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-23378 - Dell PowerScale OneFS Directory Listing Information Exposure

CVE ID : CVE-2025-23378
Published : April 10, 2025, 3:15 a.m. | 2 hours, 16 minutes ago
Description : Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26330 - Dell PowerScale OneFS Local Privilege Escalation Authorization Bypass

CVE ID : CVE-2025-26330
Published : April 10, 2025, 3:15 a.m. | 2 hours, 16 minutes ago
Description : Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26479 - Dell PowerScale OneFS Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-26479
Published : April 10, 2025, 3:15 a.m. | 2 hours, 16 minutes ago
Description : Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26480 - Dell PowerScale OneFS Denial of Service Vulnerability

CVE ID : CVE-2025-26480
Published : April 10, 2025, 3:15 a.m. | 2 hours, 16 minutes ago
Description : Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27690 - Dell PowerScale OneFS Default Password Vulnerability (Remote Authentication Bypass)

CVE ID : CVE-2025-27690
Published : April 10, 2025, 3:15 a.m. | 2 hours, 16 minutes ago
Description : Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3489 - Nababur Simple-User-Management-System Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-3489
Published : April 10, 2025, 4:15 a.m. | 1 hour, 16 minutes ago
Description : A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument name/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3102 - WordPress SureTriggers Plugin Authentication Bypass Vulnerability

CVE ID : CVE-2025-3102
Published : April 10, 2025, 5:15 a.m. | 16 minutes ago
Description : The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32208 - Hive Support Missing Authorization Vulnerability

CVE ID : CVE-2025-32208
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in Hive Support Hive Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hive Support: from n/a through 1.2.2.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32209 - Totalprocessing WooCommerce Path Traversal Vulnerability

CVE ID : CVE-2025-32209
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Total processing card payments for WooCommerce allows Path Traversal. This issue affects Total processing card payments for WooCommerce: from n/a through 7.1.5.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32210 - CreativeMindsSolutions CM Registration and Invitation Codes Missing Authorization Vulnerability

CVE ID : CVE-2025-32210
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in CreativeMindsSolutions CM Registration and Invitation Codes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CM Registration and Invitation Codes: from n/a through 2.5.2.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32212 - Specia Companion Missing Authorization Vulnerability

CVE ID : CVE-2025-32212
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in Specia Theme Specia Companion allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specia Companion: from n/a through 4.6.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32213 - Flothemesplugins Flo Forms Missing Authorization

CVE ID : CVE-2025-32213
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in flothemesplugins Flo Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Flo Forms: from n/a through 1.0.43.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32214 - Hive Support Cross-Site Scripting

CVE ID : CVE-2025-32214
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support allows Stored XSS. This issue affects Hive Support: from n/a through 1.2.2.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32215 - Ability, Inc Accessibility Suite Unrestricted File Upload Stored XSS Vulnerability

CVE ID : CVE-2025-32215
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32216 - Spider Elements – Addons for Elementor Missing Authorization Vulnerability

CVE ID : CVE-2025-32216
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in Spider Themes Spider Elements – Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Spider Elements – Addons for Elementor: from n/a through 1.6.2.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32221 - Spider Themes EazyDocs Missing Authorization Vulnerability

CVE ID : CVE-2025-32221
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in Spider Themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EazyDocs: from n/a through 2.6.4.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32227 - Asgaros Forum Authentication Bypass

CVE ID : CVE-2025-32227
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum allows Identity Spoofing. This issue affects Asgaros Forum: from n/a through 3.0.0.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32228 - WP Messiah Ai Image Alt Text Generator for WP Sensitive Information Exposure

CVE ID : CVE-2025-32228
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah Ai Image Alt Text Generator for WP. This issue affects Ai Image Alt Text Generator for WP: from n/a through 1.0.8.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32230 - Themeum Tutor LMS XSS

CVE ID : CVE-2025-32230
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32236 - Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Missing Authorization Vulnerability

CVE ID : CVE-2025-32236
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic. This issue affects Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic: from n/a through 1.9.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32240 - Site Notify Missing Authorization Vulnerability

CVE ID : CVE-2025-32240
Published : April 10, 2025, 8:15 a.m. | 1 hour, 20 minutes ago
Description : Missing Authorization vulnerability in NotFound Site Notify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Site Notify: from n/a through 1.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...