CVE tracker
367 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-23167 - Node.js HTTP Smuggling Vulnerability

CVE ID : CVE-2025-23167
Published : May 19, 2025, 2:15 a.m. | 3 hours, 10 minutes ago
Description : A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination. Impact: * This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4905 - Apache iop-apl-uw Basestation3 Deserialization Vulnerability

CVE ID : CVE-2025-4905
Published : May 19, 2025, 2:15 a.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the file basestation3/QC.py. The manipulation of the argument qc_file leads to deserialization. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The code maintainer tagged the issue as closed. But there is no new commit nor release in the GitHub repository available so far.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4906 - "PHPGurukul Notice Board System SQL Injection Vulnerability"

CVE ID : CVE-2025-4906
Published : May 19, 2025, 3:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Notice Board System 1.0. It has been classified as critical. Affected is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4907 - PHPGurukul Daily Expense Tracker System SQL Injection Vulnerability

CVE ID : CVE-2025-4907
Published : May 19, 2025, 3:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4908 - PHPGurukul Daily Expense Tracker System SQL Injection Vulnerability

CVE ID : CVE-2025-4908
Published : May 19, 2025, 3:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability classified as critical has been found in PHPGurukul Daily Expense Tracker System 1.1. This affects an unknown part of the file /expense-datewise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4909 - SourceCodester Client Database Management System Directory Traversal

CVE ID : CVE-2025-4909
Published : May 19, 2025, 4:15 a.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4910 - PHPGurukul Zoo Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4910
Published : May 19, 2025, 4:15 a.m. | 1 hour, 10 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue affects some unknown processing of the file /admin/edit-animal-details.php. The manipulation of the argument aname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1627 - Qi Blocks WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-1627
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2524 - Ninja Forms WordPress Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2524
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2560 - Ninja Forms Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2560
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2561 - Ninja Forms Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-2561
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4477 - ThreatSonar Anti-Ransomware TeamT5 Privilege Escalation Vulnerability

CVE ID : CVE-2025-4477
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4913 - PHPGurukul Auto Taxi Stand Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4913
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4914 - PHPGurukul Auto Taxi Stand Management System SQL Injection

CVE ID : CVE-2025-4914
Published : May 19, 2025, 6:15 a.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4915 - PHPGurukul Auto Taxi Stand Management System SQL Injection

CVE ID : CVE-2025-4915
Published : May 19, 2025, 7:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/auto-taxi-entry-detail.php. The manipulation of the argument price leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4916 - PHPGurukul Auto Taxi Stand Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4916
Published : May 19, 2025, 7:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-37891 - ALSA UMP Buffer Overflow Vulnerability

CVE ID : CVE-2025-37891
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: Fix buffer overflow at UMP SysEx message conversion The conversion function from MIDI 1.0 to UMP packet contains an internal buffer to keep the incoming MIDI bytes, and its size is 4, as it was supposed to be the max size for a MIDI1 UMP packet data. However, the implementation overlooked that SysEx is handled in a different format, and it can be up to 6 bytes, as found in do_convert_to_ump(). It leads eventually to a buffer overflow, and may corrupt the memory when a longer SysEx message is received. The fix is simply to extend the buffer size to 6 to fit with the SysEx UMP message.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46801 - PgPool Global Development Group Pgpool-II Authentication Bypass

CVE ID : CVE-2025-46801
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47749 - SFT VS6 Edit Data Pointer Corruption Buffer Overflow

CVE ID : CVE-2025-47749
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47750 - SFT VS Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-47750
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47751 - V-SFT Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-47751
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6EditData!CDataRomErrorCheck::MacroCommandCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...