CVE tracker
367 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-3568 - Webkul Krayin CRM SVG File Handler Cross Site Scripting Vulnerability

CVE ID : CVE-2025-3568
Published : April 14, 2025, 2:15 p.m. | 2 hours, 11 minutes ago
Description : A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3569 - "JamesZBL/code-projects db-hospital-drug Remote Code Execution via Improper Authorization"

CVE ID : CVE-2025-3569
Published : April 14, 2025, 2:15 p.m. | 2 hours, 11 minutes ago
Description : A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-49825 - IBM Robotic Process Automation Session Impersonation Vulnerability

CVE ID : CVE-2024-49825
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2160 - Pega Platform Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2160
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2161 - Pega Platform Mashup Cross-Site Scripting

CVE ID : CVE-2025-2161
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2424 - Mattermost File Information Disclosure

CVE ID : CVE-2025-2424
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2475 - Mattermost Bot Conversion Cache Invalidation Vulnerability

CVE ID : CVE-2025-2475
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32909 - Libsoup NULL Pointer Dereference Vulnerability

CVE ID : CVE-2025-32909
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32910 - "Libsoup NULL Pointer Dereference Authentication Vulnerability"

CVE ID : CVE-2025-32910
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32912 - "Libsoup HTTP Server NULL Pointer Dereference Vulnerability"

CVE ID : CVE-2025-32912
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32914 - Apache Libsoup Out-of-Bounds Read Vulnerability

CVE ID : CVE-2025-32914
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32930 - Cisco Unknown Vulnerability Type

CVE ID : CVE-2025-32930
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3570 - JamesZBL/code-projects db-hospital-drug Cross Site Scripting Vulnerability

CVE ID : CVE-2025-3570
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of the file ContentController.java. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3571 - Fannuo Enterprise Content Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3571
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/cms_chip.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22371 - SicommNet BASEC SQL Injection

CVE ID : CVE-2025-22371
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allows an unauthenticated remote attacker to Bypass Authentication and execute arbitrary SQL commands. This issue at least affects BASEC for the date of 14 Dec 2021 onwards. It is very likely that this vulnerability has been present in the solution before that. As of the date of this CVE record, there has been no patch
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22372 - SicommNet BASEC Unprotected Passwords Vulnerability

CVE ID : CVE-2025-22372
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily. This issue affects BASEC: from 14 Dec 2021.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22373 - SicommNet BASEC Web Page Generation Vulnerability (Cross-site Scripting)

CVE ID : CVE-2025-22373
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SicommNet BASEC on SaaS allows Reflected XSS, XSS Through HTTP Query Strings, Rendering of Arbitrary HTML and alternation of CSS Styles This issue affects BASEC: from 14 Dec 2021.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2572 - WhatsUp Gold Database Manipulation Vulnerability

CVE ID : CVE-2025-2572
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32931 - DevDojo Voyager Command Injection Vulnerability

CVE ID : CVE-2025-32931
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29720 - Dify SSRF

CVE ID : CVE-2025-29720
Published : April 14, 2025, 5:15 p.m. | 2 hours, 52 minutes ago
Description : Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3277 - SQLite Heap Buffer Overflow

CVE ID : CVE-2025-3277
Published : April 14, 2025, 5:15 p.m. | 2 hours, 52 minutes ago
Description : An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...