CVE tracker
369 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-31262 - Apple VisionOS File System Permissions Vulnerability

CVE ID : CVE-2025-31262
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32920 - TemplateInvaders WooCommerce Wishlist Stored Cross-Site Scripting (XSS)

CVE ID : CVE-2025-32920
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.9.2.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4876 - ConnectWise Risk Assessment Hardcoded AES Key Disclosure

CVE ID : CVE-2025-4876
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the key can be used to decrypt CSV input files used for authenticated network scanning.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4938 - PHPGurukul Employee Record Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4938
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registererms.php. The manipulation of the argument Email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4939 - PHPGurukul Credit Card Application Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-4939
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4948 - Libsoup Integer Underflow Denial-of-Service Vulnerability

CVE ID : CVE-2025-4948
Published : May 19, 2025, 4:15 p.m. | 1 hour, 10 minutes ago
Description : A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32928 - ThemeGoods Altair Object Injection Vulnerability

CVE ID : CVE-2025-32928
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in ThemeGoods Altair allows Object Injection.This issue affects Altair: from n/a through 5.2.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39348 - ThemeGoods Grand Restaurant WordPress Object Injection Vulnerability

CVE ID : CVE-2025-39348
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39349 - CiyaShop Object Injection Vulnerability

CVE ID : CVE-2025-39349
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop allows Object Injection.This issue affects CiyaShop: from n/a through 4.18.0.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39350 - Rocket Apps wProject Missing Authorization Vulnerability

CVE ID : CVE-2025-39350
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39352 - ThemeGoods Grand Restaurant WordPress Missing Authorization Vulnerability

CVE ID : CVE-2025-39352
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39354 - ThemeGoods Grand Conference Object Injection Vulnerability

CVE ID : CVE-2025-39354
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference allows Object Injection.This issue affects Grand Conference: from n/a through 5.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39355 - FAT Services Booking SQL Injection

CVE ID : CVE-2025-39355
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39356 - Chimpstudio Foodbakery Sticky Cart Object Injection Vulnerability

CVE ID : CVE-2025-39356
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through 3.2.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39357 - Mojoomla Hospital Management System SQL Injection

CVE ID : CVE-2025-39357
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39365 - Rocket Apps wProject Cross-site Scripting

CVE ID : CVE-2025-39365
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProject allows Reflected XSS.This issue affects wProject: from n/a before 5.8.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39366 - Rocket Apps wProject Privilege Escalation Vulnerability

CVE ID : CVE-2025-39366
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39372 - WordPress Events Calendar Registration & Tickets Cross-site Scripting

CVE ID : CVE-2025-39372
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39380 - Mojoomla Hospital Management System File Upload Vulnerability

CVE ID : CVE-2025-39380
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39386 - Mojoomla Hospital Management System SQL Injection

CVE ID : CVE-2025-39386
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-39389 - Solid Plugins AnalyticsWP SQL Injection

CVE ID : CVE-2025-39389
Published : May 19, 2025, 8:15 p.m. | 1 hour, 10 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins AnalyticsWP allows SQL Injection.This issue affects AnalyticsWP: from n/a through 2.1.2.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...