CVE tracker
306 subscribers
4.34K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-46546 - Sherpa Orchestrator Blind SQL Injection Vulnerability

CVE ID : CVE-2025-46546
Published : April 25, 2025, 3:15 a.m. | 1 hour, 27 minutes ago
Description : In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46547 - Sherpa Orchestrator Cross-Site Request Forgery (XSS, SQL Injection) Vulnerability

CVE ID : CVE-2025-46547
Published : April 25, 2025, 3:15 a.m. | 1 hour, 27 minutes ago
Description : In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46595 - Backdrop CMS Flag Module Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-46595
Published : April 25, 2025, 3:15 a.m. | 1 hour, 27 minutes ago
Description : An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow crafted HTML to result in Cross Site Scripting. This is mitigated by the fact that an attacker must have a role with permission to create links on the website, for example: create or edit comments or content with a filtered text format.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3752 - Able Player WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-3752
Published : April 25, 2025, 5:15 a.m. | 3 hours, 27 minutes ago
Description : The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3775 - ShopLentor WooCommerce Builder SSRF Vulnerability

CVE ID : CVE-2025-3775
Published : April 25, 2025, 5:15 a.m. | 3 hours, 27 minutes ago
Description : The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, and can be used to query and modify information from internal services.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46599 - K3s Kubernetes Kubelet ReadWritePort Remote Authentication Bypass

CVE ID : CVE-2025-46599
Published : April 25, 2025, 5:15 a.m. | 3 hours, 27 minutes ago
Description : CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0671 - Icegram Express WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-0671
Published : April 25, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2580 - Bit Form WordPress Contact Form Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2580
Published : April 25, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3511 - Mitsubishi Electric Corporation CC-Link IE TSN Denial of Service Remote Buffer Overflow

CVE ID : CVE-2025-3511
Published : April 25, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module and CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY allows a remote unauthenticated attacker to cause a Denial of Service condition in the products by sending specially crafted UDP packets.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3861 - WordPress Prevent Direct Access Unauthorized Access Vulnerability

CVE ID : CVE-2025-3861
Published : April 25, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to access and change the protection status of media.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3923 - WordPress Prevent Direct Access - Sensitive Information Exposure

CVE ID : CVE-2025-3923
Published : April 25, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to extract sensitive data including files protected by the plugin if the attacker can determine the file name.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46613 - OpenPLC Server Memory Corruption

CVE ID : CVE-2025-46613
Published : April 25, 2025, 6:15 a.m. | 2 hours, 26 minutes ago
Description : OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2238 - Vikinger WordPress Privilege Escalation Vulnerability

CVE ID : CVE-2025-2238
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator-level.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3743 - WooCommerce Upsell Funnel Builder Order Manipulation Vulnerability

CVE ID : CVE-2025-3743
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3866 - Google Plus One Social Share Button CSRF Vulnerability

CVE ID : CVE-2025-3866
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3867 - WordPress Ajax Comment Form CST CSRF

CVE ID : CVE-2025-3867
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3868 - WordPress Custom Admin-Bar Favorites Reflected Cross-Site Scripting

CVE ID : CVE-2025-3868
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46616 - Quantum StorNext Web GUI API RCE

CVE ID : CVE-2025-46616
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46617 - Quantum StorNext Web GUI API Unauthorized Configuration Access and Modification

CVE ID : CVE-2025-46617
Published : April 25, 2025, 7:15 a.m. | 1 hour, 26 minutes ago
Description : Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46482 - MyThemeShop WP Quiz Stored Cross-site Scripting Vulnerability

CVE ID : CVE-2025-46482
Published : April 25, 2025, 8:15 a.m. | 27 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz allows Stored XSS.This issue affects WP Quiz: from n/a through 2.0.10.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46535 - AlphaEfficiencyTeam Custom Login and Registration Missing Authorization Vulnerability

CVE ID : CVE-2025-46535
Published : April 25, 2025, 8:15 a.m. | 27 minutes ago
Description : Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...