CVE tracker
388 subscribers
5.54K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-26959 - Quý Lê 91 Administrator Z Missing Authorization Privilege Escalation

CVE ID : CVE-2025-26959
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Missing Authorization vulnerability in Quý Lê 91 Administrator Z allows Privilege Escalation. This issue affects Administrator Z: from n/a through 2025.03.24.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26982 - Eric-Oliver Mächler DSGVO Youtube Cross-site Scripting Vulnerability

CVE ID : CVE-2025-26982
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube allows DOM-Based XSS. This issue affects DSGVO Youtube: from n/a through 1.5.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26990 - Royal Elementor Addons SSRF

CVE ID : CVE-2025-26990
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26992 - Fatcatapps Landing Page Cat Cross-site Scripting Vulnerability

CVE ID : CVE-2025-26992
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat allows Reflected XSS. This issue affects Landing Page Cat: from n/a through 1.7.8.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30962 - NotFound FS Poster Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-30962
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FS Poster allows Reflected XSS. This issue affects FS Poster: from n/a through 6.5.8.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30964 - EPC Photography SSRF Vulnerability

CVE ID : CVE-2025-30964
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Server-Side Request Forgery (SSRF) vulnerability in EPC Photography. This issue affects Photography: from n/a through 7.5.2.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30965 - WPJobBoard CSRF

CVE ID : CVE-2025-30965
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30985 - GNUCommerce NotFound Object Injection Vulnerability

CVE ID : CVE-2025-30985
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31011 - ReichertBrothers SimplyRETS Real Estate IDX Cross-site Scripting Vulnerability

CVE ID : CVE-2025-31011
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers SimplyRETS Real Estate IDX allows Reflected XSS. This issue affects SimplyRETS Real Estate IDX: from n/a through 3.0.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32929 - UKR Solution Barcode Generator for WooCommerce Missing Authorization Vulnerability

CVE ID : CVE-2025-32929
Published : April 15, 2025, 12:15 p.m. | 2 hours, 14 minutes ago
Description : Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Barcode Generator for WooCommerce: from n/a through 2.0.4.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32102 - CrushFTP SSRF Vulnerability

CVE ID : CVE-2025-32102
Published : April 15, 2025, 1:15 p.m. | 1 hour, 13 minutes ago
Description : CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32103 - CrushFTP SMB Directory Traversal Vulnerability

CVE ID : CVE-2025-32103
Published : April 15, 2025, 1:15 p.m. | 1 hour, 13 minutes ago
Description : CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32944 - PeerTube Denial of Service (DoS) via Uncaught Exception in Archive Import

CVE ID : CVE-2025-32944
Published : April 15, 2025, 1:15 p.m. | 1 hour, 13 minutes ago
Description : The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32945 - PeerTube Cross-Site Playlist Manipulation

CVE ID : CVE-2025-32945
Published : April 15, 2025, 1:15 p.m. | 1 hour, 13 minutes ago
Description : The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32946 - Mastodon Playlist Hijacking Vulnerability

CVE ID : CVE-2025-32946
Published : April 15, 2025, 1:15 p.m. | 1 hour, 13 minutes ago
Description : This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3608 - Firefox NSHttpTransaction Memory Corruption Vulnerability

CVE ID : CVE-2025-3608
Published : April 15, 2025, 1:15 p.m. | 1 hour, 13 minutes ago
Description : A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29280 - PerfreeBlog Cross-Site Scripting (XSS)

CVE ID : CVE-2025-29280
Published : April 15, 2025, 2:15 p.m. | 4 hours, 13 minutes ago
Description : Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27980 - Cashbook File Read Vulnerability

CVE ID : CVE-2025-27980
Published : April 15, 2025, 3:16 p.m. | 3 hours, 13 minutes ago
Description : cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28142 - Edimax Router Command Injection Vulnerability

CVE ID : CVE-2025-28142
Published : April 15, 2025, 3:16 p.m. | 3 hours, 13 minutes ago
Description : Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28143 - Edimax Router Command Injection Vulnerability

CVE ID : CVE-2025-28143
Published : April 15, 2025, 3:16 p.m. | 3 hours, 13 minutes ago
Description : Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28144 - Edimax BR-6478AC Router Stack Overflow Vulnerability

CVE ID : CVE-2025-28144
Published : April 15, 2025, 3:16 p.m. | 3 hours, 13 minutes ago
Description : Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...