CVE tracker
367 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-2161 - Pega Platform Mashup Cross-Site Scripting

CVE ID : CVE-2025-2161
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2424 - Mattermost File Information Disclosure

CVE ID : CVE-2025-2424
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2475 - Mattermost Bot Conversion Cache Invalidation Vulnerability

CVE ID : CVE-2025-2475
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user account is converted to a bot which allows an attacker to login to the bot exactly one time via normal credentials.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32909 - Libsoup NULL Pointer Dereference Vulnerability

CVE ID : CVE-2025-32909
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32910 - "Libsoup NULL Pointer Dereference Authentication Vulnerability"

CVE ID : CVE-2025-32910
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32912 - "Libsoup HTTP Server NULL Pointer Dereference Vulnerability"

CVE ID : CVE-2025-32912
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32914 - Apache Libsoup Out-of-Bounds Read Vulnerability

CVE ID : CVE-2025-32914
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32930 - Cisco Unknown Vulnerability Type

CVE ID : CVE-2025-32930
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3570 - JamesZBL/code-projects db-hospital-drug Cross Site Scripting Vulnerability

CVE ID : CVE-2025-3570
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of the file ContentController.java. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3571 - Fannuo Enterprise Content Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3571
Published : April 14, 2025, 3:15 p.m. | 1 hour, 11 minutes ago
Description : A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/cms_chip.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22371 - SicommNet BASEC SQL Injection

CVE ID : CVE-2025-22371
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allows an unauthenticated remote attacker to Bypass Authentication and execute arbitrary SQL commands. This issue at least affects BASEC for the date of 14 Dec 2021 onwards. It is very likely that this vulnerability has been present in the solution before that. As of the date of this CVE record, there has been no patch
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22372 - SicommNet BASEC Unprotected Passwords Vulnerability

CVE ID : CVE-2025-22372
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are either stored in plain text using reversible encryption, allowing an attacker with sufficient privileges to extract plain text passwords easily. This issue affects BASEC: from 14 Dec 2021.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22373 - SicommNet BASEC Web Page Generation Vulnerability (Cross-site Scripting)

CVE ID : CVE-2025-22373
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SicommNet BASEC on SaaS allows Reflected XSS, XSS Through HTTP Query Strings, Rendering of Arbitrary HTML and alternation of CSS Styles This issue affects BASEC: from 14 Dec 2021.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2572 - WhatsUp Gold Database Manipulation Vulnerability

CVE ID : CVE-2025-2572
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32931 - DevDojo Voyager Command Injection Vulnerability

CVE ID : CVE-2025-32931
Published : April 14, 2025, 4:15 p.m. | 3 hours, 52 minutes ago
Description : DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29720 - Dify SSRF

CVE ID : CVE-2025-29720
Published : April 14, 2025, 5:15 p.m. | 2 hours, 52 minutes ago
Description : Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3277 - SQLite Heap Buffer Overflow

CVE ID : CVE-2025-3277
Published : April 14, 2025, 5:15 p.m. | 2 hours, 52 minutes ago
Description : An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3585 - Westboy CicadasCMS Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-3585
Published : April 14, 2025, 6:15 p.m. | 1 hour, 52 minutes ago
Description : A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1782 - HylaFAX Enterprise Web Interface and AvantFAX File Inclusion Vulnerability

CVE ID : CVE-2025-1782
Published : April 14, 2025, 7:15 p.m. | 52 minutes ago
Description : In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3587 - ZeroWdd/Code-Projects StudentManager Remote Authorization Bypass

CVE ID : CVE-2025-3587
Published : April 14, 2025, 8:15 p.m. | 2 hours, 11 minutes ago
Description : A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherList. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2022-43840 - IBM Aspera Console XPath Injection Vulnerability

CVE ID : CVE-2022-43840
Published : April 14, 2025, 9:15 p.m. | 1 hour, 11 minutes ago
Description : IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...