CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-41059 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41059
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tablesorter.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41060 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41060
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tree.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41061 - Stored Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41061
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/uploadify.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41062 - Reflected Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41062
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41063 - Reflected Cross-Site Scripting vulnerability in appRain CMF

CVE ID : CVE-2025-41063
Published : Sept. 4, 2025, 12:15 p.m. | 2 hours, 50 minutes ago
Description : A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 's' parameter in /apprain/developer/debug-log/db.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7385 - SQL Injection in GOV CMS

CVE ID : CVE-2025-7385
Published : Sept. 4, 2025, 1:15 p.m. | 1 hour, 50 minutes ago
Description : Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7388 - Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface

CVE ID : CVE-2025-7388
Published : Sept. 4, 2025, 1:15 p.m. | 1 hour, 50 minutes ago
Description : It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execute OS commands under the delegated authority of the AdminServer process.  An RMI interface permitted manipulation of a configuration property with inadequate input validation leading to OS command injection.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8311 - dotCMS Boolean-based Blind SQL Injection Vulnerability

CVE ID : CVE-2025-8311
Published : Sept. 4, 2025, 2:12 p.m. | 53 minutes ago
Description : dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a comma-separated list of site identifiers or keys. The vulnerability was triggered via the sites parameter, which was directly concatenated into a SQL query without proper sanitization. Exploitation allowed an authenticated attacker with low privileges to extract data from database, perform privilege escalation, or trigger denial-of-service conditions. The vulnerability was verified using tools such as SQLMap and confirmed to allow full database exfiltration and potential denial-of-service conditions via crafted payloads. The vulnerability is fixed in the following versions of dotCMS stack: 25.08.14 / 25.07.10-1v2 LTS / 24.12.27v10 LTS / 24.04.24v21 LTS
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6785 - Tesla Model 3 Physical CAN Bus Injection

CVE ID : CVE-2025-6785
Published : Sept. 4, 2025, 2:13 p.m. | 52 minutes ago
Description : Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle.  Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57263 - VX Guestbook SQL Injection

CVE ID : CVE-2025-57263
Published : Sept. 4, 2025, 2:15 p.m. | 50 minutes ago
Description : An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2694 - IBM Sterling B2B Integrator cross-site scripting

CVE ID : CVE-2025-2694
Published : Sept. 4, 2025, 2:43 p.m. | 22 minutes ago
Description : IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2667 - IBM Sterling B2B Integrator information disclosure

CVE ID : CVE-2025-2667
Published : Sept. 4, 2025, 2:45 p.m. | 20 minutes ago
Description : IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose sensitive system information about the server to a privileged user that could aid in further attacks against the system.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48538 - Android PackageManagerService Local Denial of Service Vulnerability

CVE ID : CVE-2025-48538
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48539 - Google SendPacketToPeer Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-48539
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48540 - Apache Rpc Local Privilege Escalation

CVE ID : CVE-2025-48540
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48541 - Android FaceSettings Biometric Unlock Privilege Escalation

CVE ID : CVE-2025-48541
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48542 - Android AccountManagerService Resource Exhaustion Denial of Service

CVE ID : CVE-2025-48542
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48543 - Google Chrome Android Use After Free Sandbox Escalation

CVE ID : CVE-2025-48543
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48544 - Android Device SQL Injection Local Privilege Escalation

CVE ID : CVE-2025-48544
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48545 - Android AccountManagerService Confused Deputy Local Privilege Escalation

CVE ID : CVE-2025-48545
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48546 - Android SafeActivityOptions Local Privilege Escalation

CVE ID : CVE-2025-48546
Published : Sept. 4, 2025, 6:34 p.m. | 32 minutes ago
Description : In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...