CVE tracker
315 subscribers
4.47K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-48370 - Supabase Auth URL Path Traversal Vulnerability

CVE ID : CVE-2025-48370
Published : May 27, 2025, 4:15 p.m. | 1 hour, 15 minutes ago
Description : auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.69.1, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called. Implementations that follow security best practice and validate user controlled inputs, such as the userId are not affected by this. This issue has been patched in version 2.69.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5248 - PHPGurukul Company Visitor Management System SQL Injection Vulnerability

CVE ID : CVE-2025-5248
Published : May 27, 2025, 4:15 p.m. | 1 hour, 15 minutes ago
Description : A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affected is an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-49196 - Samsung Mobile Processor Exynos GPU Type Confusion Denial of Service

CVE ID : CVE-2024-49196
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22377 - Samsung Exynos Heap-based Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-22377
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23247 - NVIDIA CUDA Toolkit ELF Buffer Overflow Vulnerability

CVE ID : CVE-2025-23247
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a malformed ELF file. A successful exploit of this vulnerability might lead to arbitrary code execution.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48057 - Icinga 2 OpenSSL Certificate Validation Bypass

CVE ID : CVE-2025-48057
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5249 - PHPGurukul News Portal Project SQL Injection Vulnerability

CVE ID : CVE-2025-5249
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-category.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5250 - PHPGurukul News Portal Project SQL Injection Vulnerability

CVE ID : CVE-2025-5250
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5251 - PHPGurukul News Portal Project SQL Injection Vulnerability

CVE ID : CVE-2025-5251
Published : May 27, 2025, 5:15 p.m. | 15 minutes ago
Description : A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-49197 - Samsung Exynos Wi-Fi Out-of-Bounds Access Vulnerability

CVE ID : CVE-2024-49197
Published : May 27, 2025, 6:15 p.m. | 3 hours, 15 minutes ago
Description : An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45475 - Maccms SSRF Vulnerability in Friend Link Management

CVE ID : CVE-2025-45475
Published : May 27, 2025, 6:15 p.m. | 3 hours, 15 minutes ago
Description : maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5252 - PHPGurukul News Portal Project SQL Injection Vulnerability

CVE ID : CVE-2025-5252
Published : May 27, 2025, 6:15 p.m. | 3 hours, 15 minutes ago
Description : A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-subadmin.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-13966 - ZKTeco BioTime Default Password Authentication Bypass

CVE ID : CVE-2024-13966
Published : May 27, 2025, 7:15 p.m. | 2 hours, 15 minutes ago
Description : ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2872 - Apache HTTP Server Remote Code Execution Vulnerability

CVE ID : CVE-2025-2872
Published : May 27, 2025, 7:15 p.m. | 2 hours, 15 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-47577. Reason: This candidate is a reservation duplicate of CVE-2025-47577. Notes: All CVE users should reference CVE-2025-47577 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45529 - SSCMS File Read Vulnerability

CVE ID : CVE-2025-45529
Published : May 27, 2025, 7:15 p.m. | 2 hours, 15 minutes ago
Description : An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46173 - Code-Projects Online Exam Mastering System Cross Site Scripting (XSS)

CVE ID : CVE-2025-46173
Published : May 27, 2025, 8:15 p.m. | 1 hour, 15 minutes ago
Description : code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5063 - Google Chrome Use After Free in Compositing Vulnerability

CVE ID : CVE-2025-5063
Published : May 27, 2025, 9:15 p.m. | 15 minutes ago
Description : Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5064 - Google Chrome Background Fetch API Cross-Origin Data Leak Vulnerability

CVE ID : CVE-2025-5064
Published : May 27, 2025, 9:15 p.m. | 15 minutes ago
Description : Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5065 - Google Chrome FileSystemAccess API UI Spoofing Vulnerability

CVE ID : CVE-2025-5065
Published : May 27, 2025, 9:15 p.m. | 15 minutes ago
Description : Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5066 - Google Chrome Android Messages UI Spoofing

CVE ID : CVE-2025-5066
Published : May 27, 2025, 9:15 p.m. | 15 minutes ago
Description : Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5067 - Inappropriate implementation in Tab Strip in Googl

CVE ID : CVE-2025-5067
Published : May 27, 2025, 9:15 p.m. | 15 minutes ago
Description : Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...