CVE tracker
369 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-47757 - Adobe VSFT Out-of-Bounds Read Vulnerability

CVE ID : CVE-2025-47757
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47758 - Citrix Systems VSFT Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-47758
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47759 - V-SFT Buffer Overflow Vulnerability

CVE ID : CVE-2025-47759
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47760 - Apache V-SFT Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-47760
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4917 - PHPGurukul Auto Taxi Stand Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4917
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as critical has been found in PHPGurukul Auto Taxi Stand Management System 1.0. Affected is an unknown function of the file /admin/new-autoortaxi-entry-form.php. The manipulation of the argument drivername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4923 - SourceCodester Client Database Management System Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-4923
Published : May 19, 2025, 8:15 a.m. | 1 hour, 10 minutes ago
Description : A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27566 - a-blog CMS Path Traversal Vulnerability

CVE ID : CVE-2025-27566
Published : May 19, 2025, 9:15 a.m. | 4 hours, 10 minutes ago
Description : Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.
Severity: 3.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32999 - "A-Blog CMS Cross-Site Scripting Vulnerability"

CVE ID : CVE-2025-32999
Published : May 19, 2025, 9:15 a.m. | 4 hours, 10 minutes ago
Description : Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36560 - A-Blog CMS SSRF Vulnerability

CVE ID : CVE-2025-36560
Published : May 19, 2025, 9:15 a.m. | 4 hours, 10 minutes ago
Description : Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41429 - A-Blog CMS Session Hijacking Vulnerability

CVE ID : CVE-2025-41429
Published : May 19, 2025, 9:15 a.m. | 4 hours, 10 minutes ago
Description : a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4924 - SourceCodester Client Database Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4924
Published : May 19, 2025, 9:15 a.m. | 4 hours, 10 minutes ago
Description : A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4925 - PHPGurukul Daily Expense Tracker System SQL Injection Vulnerability

CVE ID : CVE-2025-4925
Published : May 19, 2025, 9:15 a.m. | 4 hours, 10 minutes ago
Description : A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4926 - A vulnerability was found in PHPGurukul Car Rental

CVE ID : CVE-2025-4926
Published : May 19, 2025, 10:15 a.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/post-avehical.php. The manipulation of the argument img1/img2/img3/img4/img5 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4927 - PHPGurukul Online Marriage Registration System SQL Injection Vulnerability

CVE ID : CVE-2025-4927
Published : May 19, 2025, 10:15 a.m. | 3 hours, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Online Marriage Registration System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/between-dates-application-report.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4928 - Projectworlds Online Lawyer Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4928
Published : May 19, 2025, 11:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in projectworlds Online Lawyer Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /save_lawyer_edit_profile.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4929 - Campcodes Online Shopping Portal SQL Injection Vulnerability

CVE ID : CVE-2025-4929
Published : May 19, 2025, 11:15 a.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file /my-account.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2099 - Huggingface Transformers ReDoS Vulnerability

CVE ID : CVE-2025-2099
Published : May 19, 2025, 12:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4930 - Campcodes Online Shopping Portal SQL Injection Vulnerability

CVE ID : CVE-2025-4930
Published : May 19, 2025, 12:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /my-cart.php. The manipulation of the argument billingaddress leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4931 - Projectworlds Online Lawyer Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4931
Published : May 19, 2025, 12:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as critical was found in projectworlds Online Lawyer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /user_registation.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4936 - "Projectworlds Online Food Ordering System SQL Injection Vulnerability"

CVE ID : CVE-2025-4936
Published : May 19, 2025, 3:15 p.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in projectworlds Online Food Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin-page.php. The manipulation of the argument 1_price leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4937 - SourceCodester Apartment Visitor Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4937
Published : May 19, 2025, 3:15 p.m. | 2 hours, 10 minutes ago
Description : A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...