CVE tracker
314 subscribers
4.47K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-6120 - Assimp Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-6120
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in the library assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6121 - D-Link DIR-632 HTTP POST Request Handler Stack-Based Buffer Overflow

CVE ID : CVE-2025-6121
Published : June 16, 2025, 12:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is the function get_pure_content of the component HTTP POST Request Handler. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6122 - Code-projects Restaurant Order System SQL Injection

CVE ID : CVE-2025-6122
Published : June 16, 2025, 1:15 p.m. | 2 hours, 56 minutes ago
Description : A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6123 - Code-projects Restaurant Order System SQL Injection Vulnerability

CVE ID : CVE-2025-6123
Published : June 16, 2025, 1:15 p.m. | 2 hours, 56 minutes ago
Description : A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerability affects unknown code of the file /payment.php. The manipulation of the argument tabidNoti leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36632 - Tenable Agent Local Privilege Escalation (LPE)

CVE ID : CVE-2025-36632
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3602 - Liferay Portal Denial-of-Service GraphQL Query Depth Vulnerability

CVE ID : CVE-2025-3602
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6124 - Code-projects Restaurant Order System SQL Injection Vulnerability

CVE ID : CVE-2025-6124
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6125 - PHPGurukul Rail Pass Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-6125
Published : June 16, 2025, 2:15 p.m. | 1 hour, 56 minutes ago
Description : A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 2.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3526 - Liferay Portal SessionClicks HTTP Session Memory Consumption Denial-of-Service (DoS)

CVE ID : CVE-2025-3526
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3594 - Liferay Portal Xuggler Path Traversal Remote File Inclusion

CVE ID : CVE-2025-3594
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48976 - Apache Commons FileUpload Denial of Service (DoS) Vulnerability

CVE ID : CVE-2025-48976
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48988 - Apache Tomcat Denial of Service Vulnerability

CVE ID : CVE-2025-48988
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49124 - Apache Tomcat Windows Untrusted Search Path Vulnerability

CVE ID : CVE-2025-49124
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49125 - Apache Tomcat PreResources/PostResources Path Bypass

CVE ID : CVE-2025-49125
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4565 - Google Protocol Buffers Python Denial of Service

CVE ID : CVE-2025-4565
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6126 - PHPGurukul Rail Pass Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-6126
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6127 - PHPGurukul Nipah Virus Testing Management System Cross Site Scripting Vulnerability

CVE ID : CVE-2025-6127
Published : June 16, 2025, 3:15 p.m. | 55 minutes ago
Description : A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search-report.php. The manipulation of the argument serachdata leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49794 - "Libxml2 Use-After-Free XPath Element Parsing Vulnerability"

CVE ID : CVE-2025-49794
Published : June 16, 2025, 4:15 p.m. | 3 hours, 56 minutes ago
Description : A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49795 - XML Denial of Service in libxml2

CVE ID : CVE-2025-49795
Published : June 16, 2025, 4:15 p.m. | 3 hours, 56 minutes ago
Description : A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-49796 - Libxml2 Denial of Service Memory Corruption

CVE ID : CVE-2025-49796
Published : June 16, 2025, 4:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6128 - TOTOLINK EX1200T HTTP POST Request Handler Buffer Overflow Vulnerability

CVE ID : CVE-2025-6128
Published : June 16, 2025, 4:15 p.m. | 3 hours, 56 minutes ago
Description : A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...