CVE tracker
285 subscribers
3.88K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-21473 - Cisco Camera Data Mover (CDM) Register Write Memory Corruption Vulnerability

CVE ID : CVE-2025-21473
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21474 - Samsung Android A2dp Sink Command Queue Memory Corruption Vulnerability

CVE ID : CVE-2025-21474
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing commands from A2dp sink command queue.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21477 - Oracle NetWare CCCH Data Handling Denial of Service Vulnerability

CVE ID : CVE-2025-21477
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Transient DOS while processing CCCH data when NW sends data with invalid length.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27062 - Apache Kafka Deserialization Memory Corruption Vulnerability

CVE ID : CVE-2025-27062
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while handling client exceptions, allowing unauthorized channel access.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27065 - Cisco Security Appliance Denial of Service

CVE ID : CVE-2025-27065
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Transient DOS while processing a frame with malformed shared-key descriptor.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27066 - "Qualcomm Wi-Fi ANQP Message Processing Denial of Service"

CVE ID : CVE-2025-27066
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Transient DOS while processing an ANQP message.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27067 - Intel Graphics Memory Corruption Vulnerability

CVE ID : CVE-2025-27067
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing DDI call with invalid buffer.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27068 - Apache ExoPlayer IOCTL Memory Corruption

CVE ID : CVE-2025-27068
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing an IOCTL command with an arbitrary address.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27069 - Citrix Hypervisor Memory Corruption Vulnerability

CVE ID : CVE-2025-27069
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing DDI command calls.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27071 - Powerline Communication Firmware Buffer Overflow

CVE ID : CVE-2025-27071
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing specific files in Powerline Communication Firmware.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27072 - Cisco EAVB Header Length Information Disclosure Vulnerability

CVE ID : CVE-2025-27072
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Information disclosure while processing a packet at EAVB BE side with invalid header length.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27073 - Cisco Nexus Series: Denial of Service Vulnerability

CVE ID : CVE-2025-27073
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Transient DOS while creating NDP instance.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27075 - Qualcomm Bluetooth Host Memory Corruption Vulnerability

CVE ID : CVE-2025-27075
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27076 - Citrix NetScaler Memory Corruption Vulnerability

CVE ID : CVE-2025-27076
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Memory corruption while processing simultaneous requests via escape path.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47324 - D-Link Powerline Information Disclosure Vulnerability

CVE ID : CVE-2025-47324
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7954 - Shopware Voucher System Race Condition

CVE ID : CVE-2025-7954
Published : Aug. 6, 2025, 8:15 a.m. | 2 hours, 20 minutes ago
Description : A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7202 - Elgato Key Lights CSRF Vulnerability

CVE ID : CVE-2025-7202
Published : Aug. 6, 2025, 9:15 a.m. | 1 hour, 20 minutes ago
Description : A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely controlles the victim's lights.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8556 - CIRCL FourQ Elliptic Curve Diffie-Hellman Key Exchange Session Compromise

CVE ID : CVE-2025-8556
Published : Aug. 6, 2025, 9:15 a.m. | 1 hour, 20 minutes ago
Description : A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22469 - Siemens SIMATIC S7-1200 OS Command Injection Vulnerability

CVE ID : CVE-2025-22469
Published : Aug. 6, 2025, 10:15 a.m. | 20 minutes ago
Description : OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. An arbitrary OS command may be executed on the system with a certain non-administrative user privilege.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22470 - Siemens SIMATIC CL4/6NX Plus Lua File Execution Vulnerability

CVE ID : CVE-2025-22470
Published : Aug. 6, 2025, 10:15 a.m. | 20 minutes ago
Description : CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script may be executed on the system with the root privilege.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6013 - Vault LDAP MFA Enforcement Weakness

CVE ID : CVE-2025-6013
Published : Aug. 6, 2025, 10:15 a.m. | 20 minutes ago
Description : Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...