CVE tracker
365 subscribers
5K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-3759 - Netgear IGD Unauthenticated Configuration Change Vulnerability

CVE ID : CVE-2025-3759
Published : May 8, 2025, 10:15 a.m. | 35 minutes ago
Description : Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41450 - Danfoss AK-SM 8xxA Series Authentication Bypass

CVE ID : CVE-2025-41450
Published : May 8, 2025, 10:15 a.m. | 35 minutes ago
Description : Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to version 4.2
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2806 - TagDiv Composer WordPress Reflected Cross-Site Scripting

CVE ID : CVE-2025-2806
Published : May 8, 2025, 12:15 p.m. | 2 hours, 35 minutes ago
Description : The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3468 - NEX-Forms Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-3468
Published : May 8, 2025, 12:15 p.m. | 2 hours, 35 minutes ago
Description : The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3506 - Checkmk Unauthenticated File Access Vulnerability

CVE ID : CVE-2025-3506
Published : May 8, 2025, 12:15 p.m. | 2 hours, 35 minutes ago
Description : Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3862 - Contest Gallery WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-3862
Published : May 8, 2025, 12:15 p.m. | 2 hours, 35 minutes ago
Description : Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4208 - NEX-Forms PHP Code Execution Vulnerability

CVE ID : CVE-2025-4208
Published : May 8, 2025, 12:15 p.m. | 2 hours, 35 minutes ago
Description : The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the get_table_records function. This is due to the unsanitized use of user-supplied input in call_user_func(). This makes it possible for authenticated attackers, with Custom-level access, to execute arbitrary PHP functions that meet specific constraints (static methods or global functions accepting a single array parameter).
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-6648 - AP Page Builder Path Traversal RCE

CVE ID : CVE-2024-6648
Published : May 8, 2025, 1:15 p.m. | 1 hour, 35 minutes ago
Description : Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47729 - TeleMessage End-to-End Encryption Vulnerability

CVE ID : CVE-2025-47729
Published : May 8, 2025, 2:15 p.m. | 35 minutes ago
Description : The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
Severity: 1.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47730 - TeleMessage API Authentication Token Disclosure

CVE ID : CVE-2025-47730
Published : May 8, 2025, 2:15 p.m. | 35 minutes ago
Description : The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45818 - Slims Senayan Library Management Systems SQL Injection Vulnerability

CVE ID : CVE-2025-45818
Published : May 8, 2025, 3:15 p.m. | 3 hours, 35 minutes ago
Description : Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/item_status.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45819 - Slims Senayan Library Management Systems SQL Injection

CVE ID : CVE-2025-45819
Published : May 8, 2025, 3:15 p.m. | 3 hours, 35 minutes ago
Description : Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/author.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45820 - Slims Senayan Library Management Systems SQL Injection Vulnerability

CVE ID : CVE-2025-45820
Published : May 8, 2025, 3:15 p.m. | 3 hours, 35 minutes ago
Description : Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4207 - PostgreSQL Buffer Over-Read Denial of Service

CVE ID : CVE-2025-4207
Published : May 8, 2025, 3:15 p.m. | 3 hours, 35 minutes ago
Description : Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-51295 - PHPJabbers Event Booking Calendar HTML Injection Vulnerability

CVE ID : CVE-2023-51295
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-51328 - PHPJabbers Cleaning Business Software Stored XSS

CVE ID : CVE-2023-51328
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26842 - Znuny S/MIME Encryption Information Disclosure Vulnerability

CVE ID : CVE-2025-26842
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26844 - Znuny Cookie Without HttpOnly Flag Vulnerability

CVE ID : CVE-2025-26844
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43926 - Znuny Unauthenticated User Preference Injection Vulnerability

CVE ID : CVE-2025-43926
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values are retrieved and given as a whole to other function calls, which then might use these keys/values to affect permissions or other settings.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45841 - TOTOLINK NR1800X Remote Stack Overflow Vulnerability

CVE ID : CVE-2025-45841
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45842 - TOTOLINK NR1800X Buffer Overflow Vulnerability

CVE ID : CVE-2025-45842
Published : May 8, 2025, 4:15 p.m. | 2 hours, 35 minutes ago
Description : TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...