CVE tracker
314 subscribers
4.47K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-6118 - Das Parking Management System SQL Injection Vulnerability

CVE ID : CVE-2025-6118
Published : June 16, 2025, 11:15 a.m. | 55 minutes ago
Description : A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affects some unknown processing of the file /vehicle/search of the component API. The manipulation of the argument vehicleTypeCode leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6119 - Open Asset Import Library Assimp Use After Free Vulnerability

CVE ID : CVE-2025-6119
Published : June 16, 2025, 11:15 a.m. | 55 minutes ago
Description : A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the function Assimp::BVHLoader::ReadNodeChannels in the library assimp/code/AssetLib/BVH/BVHLoader.cpp. The manipulation of the argument pNode leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24388 - "OTRS Parameter Injection Vulnerability"

CVE ID : CVE-2025-24388
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
Severity: 3.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46710 - Apache HTTP Server Kernel Heap Corruption

CVE ID : CVE-2025-46710
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : Possible kernel exceptions caused by reading and writing kernel heap data after free.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5689 - OpenSSH Root Group Privilege Escalation

CVE ID : CVE-2025-5689
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6120 - Assimp Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6120
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in the library assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6121 - D-Link DIR-632 HTTP POST Request Handler Stack-Based Buffer Overflow

CVE ID : CVE-2025-6121
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is the function get_pure_content of the component HTTP POST Request Handler. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6122 - Code-projects Restaurant Order System SQL Injection

CVE ID : CVE-2025-6122
Published : June 16, 2025, 1:15 p.m. | 2 hours, 56 minutes ago
Description : A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6123 - Code-projects Restaurant Order System SQL Injection Vulnerability

CVE ID : CVE-2025-6123
Published : June 16, 2025, 1:15 p.m. | 2 hours, 56 minutes ago
Description : A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerability affects unknown code of the file /payment.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36632 - Tenable Agent Local Privilege Escalation (LPE)

CVE ID : CVE-2025-36632
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3602 - Liferay Portal Denial-of-Service GraphQL Query Depth Vulnerability

CVE ID : CVE-2025-3602
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6124 - Code-projects Restaurant Order System SQL Injection Vulnerability

CVE ID : CVE-2025-6124
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6125 - PHPGurukul Rail Pass Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-6125
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 2.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3526 - Liferay Portal SessionClicks HTTP Session Memory Consumption Denial-of-Service (DoS)

CVE ID : CVE-2025-3526
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3594 - Liferay Portal Xuggler Path Traversal Remote File Inclusion

CVE ID : CVE-2025-3594
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48976 - Apache Commons FileUpload Denial of Service (DoS) Vulnerability

CVE ID : CVE-2025-48976
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48988 - Apache Tomcat Denial of Service Vulnerability

CVE ID : CVE-2025-48988
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49124 - Apache Tomcat Windows Untrusted Search Path Vulnerability

CVE ID : CVE-2025-49124
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49125 - Apache Tomcat PreResources/PostResources Path Bypass

CVE ID : CVE-2025-49125
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4565 - Google Protocol Buffers Python Denial of Service

CVE ID : CVE-2025-4565
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6126 - PHPGurukul Rail Pass Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-6126
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...