CVE tracker
314 subscribers
4.46K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2024-11185 - Arista EOS VLAN Isolation Bypass

CVE ID : CVE-2024-11185
Published : May 27, 2025, 11:15 p.m. | 2 hours, 15 minutes ago
Description : On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45094 - IBM DS8900F and DS8A00 HMC Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-45094
Published : May 27, 2025, 11:15 p.m. | 2 hours, 15 minutes ago
Description : IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2796 - Arista EOS IPsec Anti-Replay Protection Vulnerability

CVE ID : CVE-2025-2796
Published : May 27, 2025, 11:15 p.m. | 2 hours, 15 minutes ago
Description : On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this vulnerability. Note: this issue does not affect VXLANSec or MACSec encryption functionality.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2826 - Arista EOS Ingress ACL Enforcement Vulnerability

CVE ID : CVE-2025-2826
Published : May 27, 2025, 11:15 p.m. | 2 hours, 15 minutes ago
Description : n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The two symptoms of this issue on the affected release and platform are: * Packets which should be permitted may be dropped and, * Packets which should be dropped may be permitted.
Severity: 2.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25025 - IBM Security Guardium Information Disclosure Vulnerability

CVE ID : CVE-2025-25025
Published : May 28, 2025, 2:15 a.m. | 3 hours, 15 minutes ago
Description : IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25026 - IBM Security Guardium Authentication Bypass Vulnerability

CVE ID : CVE-2025-25026
Published : May 28, 2025, 2:15 a.m. | 3 hours, 15 minutes ago
Description : IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25029 - IBM Security Guardium File Download Privilege Escalation

CVE ID : CVE-2025-25029
Published : May 28, 2025, 2:15 a.m. | 3 hours, 15 minutes ago
Description : IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-41839 - Apache Struts Unvalidated Redirect to Malicious Site

CVE ID : CVE-2023-41839
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48841 - Apache HTTP Server Authentication Bypass

CVE ID : CVE-2025-48841
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48842 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-48842
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48843 - Apache Struts Deserialization Vulnerability

CVE ID : CVE-2025-48843
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48844 - QNAP NAS Denial of Service

CVE ID : CVE-2025-48844
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48845 - Apache HTTP Server Authentication Bypass

CVE ID : CVE-2025-48845
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48846 - VMware Remote Code Execution

CVE ID : CVE-2025-48846
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48847 - Dropbox Unvalidated Redirect

CVE ID : CVE-2025-48847
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48848 - Citrix NetScaler HTTP Request Smuggling

CVE ID : CVE-2025-48848
Published : May 28, 2025, 4:15 a.m. | 1 hour, 15 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4800 - WordPress MasterStudy LMS Pro Arbitrary File Upload Vulnerability

CVE ID : CVE-2025-4800
Published : May 28, 2025, 6:15 a.m. | 3 hours, 15 minutes ago
Description : The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server, which may make remote code execution possible.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4009 - Evertz SVDN 3080ipx-10G PHP Web Management Interface Command Injection and Authentication Bypass

CVE ID : CVE-2025-4009
Published : May 28, 2025, 7:15 a.m. | 2 hours, 15 minutes ago
Description : The Evertz SVDN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz. This web interface has two endpoints that are vulnerable to arbitrary command injection and the authentication mechanism has a flaw leading to authentication bypass. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4947 - libcurl QUIC Certificate Verification Bypass

CVE ID : CVE-2025-4947
Published : May 28, 2025, 7:15 a.m. | 2 hours, 15 minutes ago
Description : libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5025 - libcurl wolfSSL QUIC Certificate Pinning Bypass

CVE ID : CVE-2025-5025
Published : May 28, 2025, 7:15 a.m. | 2 hours, 15 minutes ago
Description : libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-54020 - Fortinet FortiManager Authorization Bypass

CVE ID : CVE-2024-54020
Published : May 28, 2025, 8:15 a.m. | 1 hour, 15 minutes ago
Description : A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...