CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-43752 - Liferay Portal File Upload Denial of Service (DoS) Vulnerability

CVE ID : CVE-2025-43752
Published : Aug. 22, 2025, 1:16 a.m. | 3 hours ago
Description : Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored in the document_library allowing an attacker to cause a potential DDoS.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41451 - Danfoss AK-SM8xxA Series Command Injection

CVE ID : CVE-2025-41451
Published : Aug. 22, 2025, 3:15 a.m. | 1 hour ago
Description : Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41452 - Danfoss AK-SM8xxA Series Web Interface Configuration Setting Vulnerability

CVE ID : CVE-2025-41452
Published : Aug. 22, 2025, 3:15 a.m. | 1 hour ago
Description : Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8281 - Talroo WordPress Reflected Cross-Site Scripting

CVE ID : CVE-2025-8281
Published : Aug. 22, 2025, 6:15 a.m. | 2 hours, 2 minutes ago
Description : The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57699 - Western Digital Kitfox for Windows Unquoted Service Path Privilege Escalation Vulnerability

CVE ID : CVE-2025-57699
Published : Aug. 22, 2025, 7:15 a.m. | 1 hour, 2 minutes ago
Description : Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with the SYSTEM privilege.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8678 - WordPress WP Crontrol SSRF

CVE ID : CVE-2025-8678
Published : Aug. 22, 2025, 8:15 a.m. | 4 hours, 3 minutes ago
Description : The WP Crontrol plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9341 - Bouncy Castle for Java FIPS: Uncontrolled Resource Consumption in AESNativeCBC Java API

CVE ID : CVE-2025-9341
Published : Aug. 22, 2025, 9:15 a.m. | 3 hours, 2 minutes ago
Description : Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java. This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9340 - Bouncy Castle for Java BC-FIPS Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-9340
Published : Aug. 22, 2025, 10:15 a.m. | 2 hours, 2 minutes ago
Description : Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.
Severity: 0.0 | NONE
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57890 - Pierre Lannoy Sessions Cross-site Scripting

CVE ID : CVE-2025-57890
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sessions allows Stored XSS. This issue affects Sessions: from n/a through 3.2.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57891 - Wpecommerce Stored Cross-site Scripting

CVE ID : CVE-2025-57891
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS. This issue affects Recurring PayPal Donations: from n/a through 1.8.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57892 - Jeff Starr Simple Statistics for Feeds CSRF Vulnerability

CVE ID : CVE-2025-57892
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds allows Cross Site Request Forgery. This issue affects Simple Statistics for Feeds: from n/a through 20250322.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57893 - Epsiloncool WP Fast Total Search CSRF Vulnerability

CVE ID : CVE-2025-57893
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search allows Cross Site Request Forgery. This issue affects WP Fast Total Search: from n/a through 1.79.270.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57894 - WPPizza Missing Authorization Vulnerability

CVE ID : CVE-2025-57894
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Missing Authorization vulnerability in ollybach WPPizza allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPPizza: from n/a through 3.19.8.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57895 - JobWP CSRF Vulnerability

CVE ID : CVE-2025-57895
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP allows Cross Site Request Forgery. This issue affects JobWP: from n/a through 2.4.3.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57896 - Church Admin Missing Authorization Vulnerability

CVE ID : CVE-2025-57896
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : Missing Authorization vulnerability in andy_moyle Church Admin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Church Admin: from n/a through 5.0.26.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9254 - Uniong WebITR Authentication Bypass

CVE ID : CVE-2025-9254
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9255 - Uniong WebITR SQL Injection

CVE ID : CVE-2025-9255
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9256 - Uniong WebITR Arbitrary File Reading Vulnerability

CVE ID : CVE-2025-9256
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9257 - Uniong WebITR Arbitrary File Reading Vulnerability

CVE ID : CVE-2025-9257
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9258 - Uniong WebITR Arbitrary File Reading Vulnerability

CVE ID : CVE-2025-9258
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9259 - Uniong WebITR Arbitrary File Reading Vulnerability

CVE ID : CVE-2025-9259
Published : Aug. 22, 2025, 12:15 p.m. | 4 hours, 3 minutes ago
Description : WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...