CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-8424 - Citrix NetScaler ADC and Gateway Unauthenticated Remote Command Injection

CVE ID : CVE-2025-8424
Published : Aug. 26, 2025, 2:15 p.m. | 18 minutes ago
Description : Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9481 - Linksys Router Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-9481
Published : Aug. 26, 2025, 2:15 p.m. | 18 minutes ago
Description : A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function setIpv6 of the file /goform/setIpv6. The manipulation of the argument tunrd_Prefix leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9482 - "Linksys Wireless Router Stack-Based Buffer Overflow Vulnerability"

CVE ID : CVE-2025-9482
Published : Aug. 26, 2025, 2:15 p.m. | 18 minutes ago
Description : A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function portRangeForwardAdd of the file /goform/portRangeForwardAdd. The manipulation of the argument ruleName/schedule/inboundFilter/TCPPorts/UDPPorts results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9483 - Linksys RE Series Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-9483
Published : Aug. 26, 2025, 2:15 p.m. | 18 minutes ago
Description : A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function singlePortForwardAdd of the file /goform/singlePortForwardAdd. This manipulation of the argument ruleName/schedule/inboundFilter causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 9.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25736 - Kapsch TrafficCom RIS-9260 RSU Android Debug Bridge Root Access

CVE ID : CVE-2025-25736
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated root shell access to the cellular modem via the default 'kapsch' user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25737 - Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) Unprotected BIOS Authentication

CVE ID : CVE-2025-25737
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52035 - NotesCMS Stored XSS Vulnerability

CVE ID : CVE-2025-52035
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-05-08) and was fixed in commit 95322c5121dbd7070f3bd54f2848079654a0a8ea (dated 2025-03-31). The attack can be launched remotely.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52036 - NotesCMS Stored XSS Vulnerability

CVE ID : CVE-2025-52036
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-05-08), and was fixed in commit 95322c5121dbd7070f3bd54f2848079654a0a8ea (dated 2025-03-31). The attack can be launched remotely. CWE Definition of the Vulnerability: CWE-79.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52037 - NotesCMS Stored XSS Vulnerability

CVE ID : CVE-2025-52037
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-05-08), and was fixed in commit 95322c5121dbd7070f3bd54f2848079654a0a8ea (dated 2025-03-31). The attack can be launched remotely. CWE Definition of the Vulnerability: CWE-79.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52217 - SelectZero Data Observability Platform HTML Injection Vulnerability

CVE ID : CVE-2025-52217
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52218 - SelectZero Data Observability Platform Content Spoofing Vulnerability

CVE ID : CVE-2025-52218
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified parameters allows attackers to inject arbitrary text or limited HTML into the login page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52219 - SelectZero Data Observability Platform Open Redirect Vulnerability

CVE ID : CVE-2025-52219
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML Injection.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6366 - WordPress Event List Plugin Privilege Escalation Vulnerability

CVE ID : CVE-2025-6366
Published : Aug. 26, 2025, 3:15 p.m. | 3 hours, 19 minutes ago
Description : The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their capabilities to those of an administrator.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-56432 - Nagios XI Cross-Site Scripting (XSS)

CVE ID : CVE-2025-56432
Published : Aug. 26, 2025, 4:15 p.m. | 2 hours, 19 minutes ago
Description : A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57810 - jsPDF High CPU Utilization Denial of Service Vulnerability

CVE ID : CVE-2025-57810
Published : Aug. 26, 2025, 4:15 p.m. | 2 hours, 19 minutes ago
Description : jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful PNG file that results in high CPU utilization and denial of service. The vulnerability was fixed in jsPDF 3.0.2.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57813 - traP traQ Exposed OAuth Tokens in SQL Error Logs

CVE ID : CVE-2025-57813
Published : Aug. 26, 2025, 4:15 p.m. | 2 hours, 19 minutes ago
Description : traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, are recorded in log files when an error occurs during the execution of an SQL query. An attacker could intentionally trigger an SQL error by methods such as placing a high load on the database. This could allow an attacker who has the authority to view the log files to illicitly acquire the recorded sensitive information. This vulnerability has been patched in version 3.25.0. If upgrading is not possible, a temporary workaround involves reviewing access permissions for SQL error logs and strictly limiting access to prevent unauthorized users from viewing them.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1494 - IBM Cognos Command Center Clickjacking Vulnerability

CVE ID : CVE-2025-1494
Published : Aug. 26, 2025, 5:15 p.m. | 1 hour, 19 minutes ago
Description : IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-1994 - IBM Cognos Command Center Deserialization Vulnerability

CVE ID : CVE-2025-1994
Published : Aug. 26, 2025, 5:15 p.m. | 1 hour, 19 minutes ago
Description : IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2697 - IBM Cognos Command Center Open Redirect Vulnerability

CVE ID : CVE-2025-2697
Published : Aug. 26, 2025, 5:15 p.m. | 1 hour, 19 minutes ago
Description : IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36729 - "Fortinet Web Interface Unauthorized Access and Privilege Escalation"

CVE ID : CVE-2025-36729
Published : Aug. 26, 2025, 5:15 p.m. | 1 hour, 19 minutes ago
Description : A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-50974 - IPFire Calamaris Log Exporter Remote Code Execution

CVE ID : CVE-2025-50974
Published : Aug. 26, 2025, 5:15 p.m. | 1 hour, 19 minutes ago
Description : The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated remote attacker can inject arbitrary OS commands by embedding shell metacharacters in any of the following parameters BYTE_UNIT, DAY_BEGIN, DAY_END, HIST_LEVEL, MONTH_BEGIN, MONTH_END, NUM_CONTENT, NUM_DOMAINS, NUM_HOSTS, NUM_URLS, PERF_INTERVAL, YEAR_BEGIN, YEAR_END.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...