CVE tracker
362 subscribers
4.91K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-43848 - Apache Retrieval-based-Voice-Conversion-WebUI Remote Code Execution

CVE ID : CVE-2025-43848
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info function in process_ckpt.py, which uses it to load the model on that path with torch.load, which can lead to unsafe deserialization and remote code execution. As of time of publication, no known patches exist.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45236 - DBSyncer Stored XSS Vulnerability

CVE ID : CVE-2025-45236
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45237 - DBSyncer Unsecured Configuration File Access Vulnerability

CVE ID : CVE-2025-45237
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45238 - Foxcms File Deletion Vulnerability

CVE ID : CVE-2025-45238
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45239 - FoxCMS Directory Traversal Vulnerability

CVE ID : CVE-2025-45239
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4050 - Google Chrome Heap Corruption Out-of-Bounds Access Vulnerability

CVE ID : CVE-2025-4050
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4051 - Google Chrome DevTools Insufficient Data Validation Remote Code Execution

CVE ID : CVE-2025-4051
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4052 - Google Chrome DevTools Authorization Bypass

CVE ID : CVE-2025-4052
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4096 - Google Chrome Heap Buffer Overflow

CVE ID : CVE-2025-4096
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4282 - SourceCodester Oretnom23 Stock Management System CSRF Vulnerability

CVE ID : CVE-2025-4282
Published : May 5, 2025, 6:15 p.m. | 33 minutes ago
Description : A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45611 - Hope-Boot Authentication Bypass

CVE ID : CVE-2025-45611
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45612 - Xmall Authentication Bypass

CVE ID : CVE-2025-45612
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45613 - Shiro-Action Unsecured Data Disclosure

CVE ID : CVE-2025-45613
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45614 - One API User Manager Information Disclosure

CVE ID : CVE-2025-45614
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45615 - Yaoqishan Unauthenticated Administrative Privilege Escalation

CVE ID : CVE-2025-45615
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45616 - Brcc Authentication Bypass Vulnerability

CVE ID : CVE-2025-45616
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45617 - Production SSM User List Unrestricted Access

CVE ID : CVE-2025-45617
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45618 - Jeeweb Mybatis Springboot Unauthenticated Information Disclosure

CVE ID : CVE-2025-45618
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46726 - Langroid XMLToolMessage XML External Entity (XXE) Denial of Service (DoS) and Local File Information Exposure

CVE ID : CVE-2025-46726
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46730 - "MobSF ZIP Bomb Denial of Service Vulnerability"

CVE ID : CVE-2025-46730
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit teams, and external vendors. MobSF provides a feature that allows users to upload ZIP files for static analysis. Upon upload, these ZIP files are automatically extracted and stored within the MobSF directory. However, in versions up to and including 4.3.2, this functionality lacks a check on the total uncompressed size of the ZIP file, making it vulnerable to a ZIP of Death (zip bomb) attack. Due to the absence of safeguards against oversized extractions, an attacker can craft a specially prepared ZIP file that is small in compressed form but expands to a massive size upon extraction. Exploiting this, an attacker can exhaust the server's disk space, leading to a complete denial of service (DoS) not just for MobSF, but also for any other applications or websites hosted on the same server. This vulnerability can lead to complete server disruption in an organization which can affect other internal portals and tools too (which are hosted on the same server). If some organization has created their customized cloud based mobile security tool using MobSF core then an attacker can exploit this vulnerability to crash their servers. Commit 6987a946485a795f4fd38cebdb4860b368a1995d fixes this issue. As an additional mitigation, it is recommended to implement a safeguard that checks the total uncompressed size of any uploaded ZIP file before extraction. If the estimated uncompressed size exceeds a safe threshold (e.g., 100 MB), MobSF should reject the file and notify the user.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46731 - Craft CMS SSTI Remote Code Execution Vulnerability

CVE ID : CVE-2025-46731
Published : May 5, 2025, 8:15 p.m. | 2 hours, 34 minutes ago
Description : Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...