CVE tracker
307 subscribers
4.35K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-43016 - JetBrains Rider Unvalidated Archive Unpacking Vulnerability

CVE ID : CVE-2025-43016
Published : April 25, 2025, 3:15 p.m. | 1 hour, 27 minutes ago
Description : In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43862 - Dify APP Orchestration Privilege Escalation Vulnerability

CVE ID : CVE-2025-43862
Published : April 25, 2025, 3:15 p.m. | 1 hour, 27 minutes ago
Description : Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make unauthorized access and changes on the APPSs. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can access Orchestration of the APPs.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46432 - JetBrains TeamCity Base64 Credentials Exposure

CVE ID : CVE-2025-46432
Published : April 25, 2025, 3:15 p.m. | 1 hour, 27 minutes ago
Description : In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46433 - JetBrains TeamCity Path Traversal Vulnerability

CVE ID : CVE-2025-46433
Published : April 25, 2025, 3:15 p.m. | 1 hour, 27 minutes ago
Description : In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46618 - JetBrains TeamCity Stored XSS Vulnerability

CVE ID : CVE-2025-46618
Published : April 25, 2025, 3:15 p.m. | 1 hour, 27 minutes ago
Description : In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-32601 - Apache Struts Deserialization Vulnerability

CVE ID : CVE-2021-32601
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-56156 - Halo File Type Validation Bypass Vulnerability

CVE ID : CVE-2024-56156
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2068 - FileZ Open Redirect Information Disclosure

CVE ID : CVE-2025-2068
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2069 - FileZ Cross-Site Scripting (XSS)

CVE ID : CVE-2025-2069
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2070 - "FileZ XML Parsing Denial of Service"

CVE ID : CVE-2025-2070
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3928 - Commvault Web Server Remote Webshell Execution

CVE ID : CVE-2025-3928
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25775 - Codeastro Bus Ticket Booking System SQL Injection Vulnerability

CVE ID : CVE-2025-25775
Published : April 25, 2025, 5:15 p.m. | 3 hours, 27 minutes ago
Description : Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-30152 - HCL SX Cryptographic Weakness

CVE ID : CVE-2024-30152
Published : April 25, 2025, 6:15 p.m. | 2 hours, 27 minutes ago
Description : HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3935 - ScreenConnect ASP.NET ViewState Code Injection Vulnerability

CVE ID : CVE-2025-3935
Published : April 25, 2025, 7:15 p.m. | 1 hour, 27 minutes ago
Description : ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server.  The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior.  This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28128 - Mytel Telecom Online Account System Authentication Bypass

CVE ID : CVE-2025-28128
Published : April 25, 2025, 8:15 p.m. | 27 minutes ago
Description : An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32979 - NETSCOUT nGeniusONE Path Traversal Vulnerability

CVE ID : CVE-2025-32979
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32980 - NETSCOUT nGeniusONE Privilege Escalation Weakness

CVE ID : CVE-2025-32980
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Weak Sudo Configuration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32981 - NETSCOUT nGeniusONE Local File Inclusion

CVE ID : CVE-2025-32981
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32982 - NETSCOUT nGeniusONE Broken Authorization Schema Vulnerability

CVE ID : CVE-2025-32982
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32983 - NETSCOUT nGeniusONE Information Disclosure Vulnerability

CVE ID : CVE-2025-32983
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32984 - NETSCOUT nGeniusONE Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-32984
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...