CVE tracker
307 subscribers
4.35K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-46618 - JetBrains TeamCity Stored XSS Vulnerability

CVE ID : CVE-2025-46618
Published : April 25, 2025, 3:15 p.m. | 1 hour, 27 minutes ago
Description : In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-32601 - Apache Struts Deserialization Vulnerability

CVE ID : CVE-2021-32601
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-56156 - Halo File Type Validation Bypass Vulnerability

CVE ID : CVE-2024-56156
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2068 - FileZ Open Redirect Information Disclosure

CVE ID : CVE-2025-2068
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2069 - FileZ Cross-Site Scripting (XSS)

CVE ID : CVE-2025-2069
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2070 - "FileZ XML Parsing Denial of Service"

CVE ID : CVE-2025-2070
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3928 - Commvault Web Server Remote Webshell Execution

CVE ID : CVE-2025-3928
Published : April 25, 2025, 4:15 p.m. | 27 minutes ago
Description : Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25775 - Codeastro Bus Ticket Booking System SQL Injection Vulnerability

CVE ID : CVE-2025-25775
Published : April 25, 2025, 5:15 p.m. | 3 hours, 27 minutes ago
Description : Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-30152 - HCL SX Cryptographic Weakness

CVE ID : CVE-2024-30152
Published : April 25, 2025, 6:15 p.m. | 2 hours, 27 minutes ago
Description : HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3935 - ScreenConnect ASP.NET ViewState Code Injection Vulnerability

CVE ID : CVE-2025-3935
Published : April 25, 2025, 7:15 p.m. | 1 hour, 27 minutes ago
Description : ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server.  The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior.  This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28128 - Mytel Telecom Online Account System Authentication Bypass

CVE ID : CVE-2025-28128
Published : April 25, 2025, 8:15 p.m. | 27 minutes ago
Description : An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32979 - NETSCOUT nGeniusONE Path Traversal Vulnerability

CVE ID : CVE-2025-32979
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32980 - NETSCOUT nGeniusONE Privilege Escalation Weakness

CVE ID : CVE-2025-32980
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Weak Sudo Configuration.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32981 - NETSCOUT nGeniusONE Local File Inclusion

CVE ID : CVE-2025-32981
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32982 - NETSCOUT nGeniusONE Broken Authorization Schema Vulnerability

CVE ID : CVE-2025-32982
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32983 - NETSCOUT nGeniusONE Information Disclosure Vulnerability

CVE ID : CVE-2025-32983
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32984 - NETSCOUT nGeniusONE Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-32984
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32985 - NETSCOUT nGeniusONE Credential Hardcoding Vulnerability

CVE ID : CVE-2025-32985
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32986 - NETSCOUT nGeniusONE Unauthenticated Sensitive File Access

CVE ID : CVE-2025-32986
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46333 - Z2D Stride Compositor Out-of-Bounds Write

CVE ID : CVE-2025-46333
Published : April 25, 2025, 9:15 p.m. | 3 hours, 27 minutes ago
Description : z2d is a pure Zig 2D graphics library. In version 0.6.0, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, the source surface can be completely out-of-bounds on the x-axis (but not on the y-axis) by way of a negative offset. This results in an overflow of the value controlling the length of the stride. In non-safe optimization modes (consumers compiling with `ReleaseFast` or `ReleaseSmall`), this could potentially lead to invalid memory accesses or corruption. This issue is patched in version 0.6.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2801 - WordPress Create Custom Forms Plugin Arbitrary Shortcode Execution Vulnerability

CVE ID : CVE-2025-2801
Published : April 26, 2025, 4:15 a.m. | 27 minutes ago
Description : The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...