CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-9843 - Das Parking Management System Remote Information Disclosure Vulnerability

CVE ID : CVE-2025-9843
Published : Sept. 3, 2025, 1:15 a.m. | 1 hour, 37 minutes ago
Description : A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information disclosure. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9845 - Fruit Shop Management System Cross-Site Scripting

CVE ID : CVE-2025-9845
Published : Sept. 3, 2025, 1:15 a.m. | 1 hour, 37 minutes ago
Description : A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such manipulation of the argument product_code/gen_name/product_name/supplier leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-58163 - FreeScout Remote Code Execution Vulnerability

CVE ID : CVE-2025-58163
Published : Sept. 3, 2025, 2:15 a.m. | 37 minutes ago
Description : FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.185 and below, the application performs deserialization of data that can allow authenticated attackers with knowledge of the application's APP_KEY to achieve remote code execution. The vulnerability can be exploited via endpoint: `/help/{mailbox_id}/auth/{customer_id}/{hash}/{timestamp}` where the `customer_id` and `timestamp` parameters are processed through the decrypt function in `app/Helper.php` without proper validation. The vulnerable code performs decryption using Laravel's built-in encryption functions, which subsequently deserializes the decrypted payload without sanitization. This is fixed in version 1.8.186.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7039 - "LibGLib Temporary File Path Traversal Vulnerability"

CVE ID : CVE-2025-7039
Published : Sept. 3, 2025, 2:15 a.m. | 37 minutes ago
Description : A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9847 - ScriptAndTools Real Estate Management System Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-9847
Published : Sept. 3, 2025, 2:15 a.m. | 37 minutes ago
Description : A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9848 - ScriptAndTools Real Estate Management System Remote File Execution Vulnerability

CVE ID : CVE-2025-9848
Published : Sept. 3, 2025, 2:15 a.m. | 37 minutes ago
Description : A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-21478 - TIGERF Trustlet Input Validation Vulnerability

CVE ID : CVE-2023-21478
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-21479 - Android Smart Suggestions Unauthorized Schedule Registration Vulnerability

CVE ID : CVE-2023-21479
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-21480 - CertByte Privilege Escalation Vulnerability

CVE ID : CVE-2023-21480
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-21481 - Samsung Account URL Injection Vulnerability

CVE ID : CVE-2023-21481
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-21482 - Samsung Camera Unauthorized Package Installation Vulnerability

CVE ID : CVE-2023-21482
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-21483 - Galaxy Store Improper Access Control Vulnerability

CVE ID : CVE-2023-21483
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-3666 - WordPress Sticky Side Buttons Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2023-3666
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21025 - Samsung Mobile Remote Access Vulnerability - Access Control Bypass

CVE ID : CVE-2025-21025
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21026 - Samsung ImsService Permission Bypass Vulnerability

CVE ID : CVE-2025-21026
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21027 - "Google ImsService Broadcast Receiver Intent Verification Vulnerability"

CVE ID : CVE-2025-21027
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21028 - Xiaomi MiUI ThemeManager Privilege Escalation Vulnerability

CVE ID : CVE-2025-21028
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21029 - Samsung System UI Message Replay Vulnerability

CVE ID : CVE-2025-21029
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21030 - Samsung Android Privilege Escalation

CVE ID : CVE-2025-21030
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21031 - Samsung ImsService Privilege Escalation Vulnerability

CVE ID : CVE-2025-21031
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21032 - Samsung One UI Home Physical Kiosk Mode Bypass Vulnerability

CVE ID : CVE-2025-21032
Published : Sept. 3, 2025, 6:15 a.m. | 38 minutes ago
Description : Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...