CVE tracker
370 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-23983 - Tijaji Cross-Site Scripting (XSS)

CVE ID : CVE-2025-23983
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tijaji allows Reflected XSS.This issue affects Tijaji: from n/a through 1.43.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23986 - Fyrewurks Tiki Time Cross-Site Scripting

CVE ID : CVE-2025-23986
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Time allows Reflected XSS.This issue affects Tiki Time: from n/a through 1.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23988 - Ghostwriter Reflected Cross-site Scripting

CVE ID : CVE-2025-23988
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24183 - Apple macOS File System Privilege Escalation Vulnerability

CVE ID : CVE-2025-24183
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local user may be able to modify protected parts of the file system.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24184 - Apple VisionOS Memory Corruption Vulnerability

CVE ID : CVE-2025-24184
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to cause unexpected system termination.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24189 - Safari Memory Corruption Vulnerability

CVE ID : CVE-2025-24189
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : The issue was addressed with improved checks. This issue is fixed in Safari 18.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to memory corruption.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26621 - OpenCTI Prototype Pollution Denial of Service

CVE ID : CVE-2025-26621
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capability manage customizations can edit webhook that will execute javascript code. This can be abused to cause a denial of service attack by prototype pollution, making the node js server running the OpenCTI frontend become unavailable. Version 6.5.2 fixes the issue.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31185 - Apple iOS Hidden Photos Album Authentication Bypass Vulnerability

CVE ID : CVE-2025-31185
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31262 - Apple VisionOS File System Permissions Vulnerability

CVE ID : CVE-2025-31262
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32920 - TemplateInvaders WooCommerce Wishlist Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-32920
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.9.2.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4876 - ConnectWise Risk Assessment Hardcoded AES Key Disclosure

CVE ID : CVE-2025-4876
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4938 - PHPGurukul Employee Record Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4938
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registererms.php. The manipulation of the argument Email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4939 - PHPGurukul Credit Card Application Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-4939
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4948 - Libsoup Integer Underflow Denial-of-Service Vulnerability

CVE ID : CVE-2025-4948
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32928 - ThemeGoods Altair Object Injection Vulnerability

CVE ID : CVE-2025-32928
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in ThemeGoods Altair allows Object Injection.This issue affects Altair: from n/a through 5.2.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39348 - ThemeGoods Grand Restaurant WordPress Object Injection Vulnerability

CVE ID : CVE-2025-39348
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39349 - CiyaShop Object Injection Vulnerability

CVE ID : CVE-2025-39349
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop allows Object Injection.This issue affects CiyaShop: from n/a through 4.18.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39350 - Rocket Apps wProject Missing Authorization Vulnerability

CVE ID : CVE-2025-39350
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39352 - ThemeGoods Grand Restaurant WordPress Missing Authorization Vulnerability

CVE ID : CVE-2025-39352
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39354 - ThemeGoods Grand Conference Object Injection Vulnerability

CVE ID : CVE-2025-39354
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference allows Object Injection.This issue affects Grand Conference: from n/a through 5.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39355 - FAT Services Booking SQL Injection

CVE ID : CVE-2025-39355
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...