CVE tracker
305 subscribers
4.33K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2024-22351 - IBM InfoSphere Information Server Authentication Session Impersonation

CVE ID : CVE-2024-22351
Published : April 23, 2025, 11:15 p.m. | 1 hour, 26 minutes ago
Description : IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25045 - IBM InfoSphere Information Server Information Disclosure

CVE ID : CVE-2025-25045
Published : April 23, 2025, 11:15 p.m. | 1 hour, 26 minutes ago
Description : IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25046 - IBM InfoSphere Information Server DataStage Flow Designer Information Disclosure

CVE ID : CVE-2025-25046
Published : April 23, 2025, 11:15 p.m. | 1 hour, 26 minutes ago
Description : IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27580 - NIH BRICS Privilege Escalation and Account Compromise Vulnerability

CVE ID : CVE-2025-27580
Published : April 24, 2025, 12:15 a.m. | 26 minutes ago
Description : NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27581 - NIH BRICS Unauthenticated Access to InET Module

CVE ID : CVE-2025-27581
Published : April 24, 2025, 12:15 a.m. | 26 minutes ago
Description : NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46417 - Apache Picklescan SSL Exfiltration Vulnerability

CVE ID : CVE-2025-46417
Published : April 24, 2025, 1:15 a.m. | 3 hours, 26 minutes ago
Description : The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46419 - Westermo WeOS Reboot Remote Command Execution Vulnerability

CVE ID : CVE-2025-46419
Published : April 24, 2025, 1:15 a.m. | 3 hours, 26 minutes ago
Description : Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1976 - Brocade Fabric OS Root Privilege Escalation

CVE ID : CVE-2025-1976
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46374 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-46374
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46375 - Apache Struts Deserialization Vulnerability

CVE ID : CVE-2025-46375
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46376 - Cisco Webex Meeting Server Authentication Bypass

CVE ID : CVE-2025-46376
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46377 - Apache HTTP Server Arbitrary File Upload Vulnerability

CVE ID : CVE-2025-46377
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46378 - Apache HTTP Server Unvalidated User Input

CVE ID : CVE-2025-46378
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46379 - Apache Web Server Denial of Service

CVE ID : CVE-2025-46379
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46380 - Apache HTTP Server Unvalidated User Input

CVE ID : CVE-2025-46380
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46381 - Apache HTTP Server Command Injection

CVE ID : CVE-2025-46381
Published : April 24, 2025, 3:15 a.m. | 1 hour, 26 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3435 - Mang Board WP Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-3435
Published : April 24, 2025, 4:15 a.m. | 26 minutes ago
Description : The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1453 - WordPress Category Posts Widget Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-1453
Published : April 24, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2558 - "WordPress Theme-Wound LFI Vulnerability"

CVE ID : CVE-2025-2558
Published : April 24, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32730 - i-PRO Co., Ltd. Surveillance Cameras and Recorders Cryptographic Key Hard-Coded Authentication Bypass

CVE ID : CVE-2025-32730
Published : April 24, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-35965 - Mattermost Denial-of-Service DoS Vulnerability

CVE ID : CVE-2025-35965
Published : April 24, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...