CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-56200 - Validator.js URL Validation Bypass Cross-Site Scripting and Open Redirect Vulnerability

CVE ID : CVE-2025-56200
Published : Sept. 30, 2025, 6:15 p.m. | 1 hour, 11 minutes ago
Description : A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-56513 - NiceHash QuickMiner Unvalidated HTTP Updates Remote Code Execution

CVE ID : CVE-2025-56513
Published : Sept. 30, 2025, 6:15 p.m. | 1 hour, 11 minutes ago
Description : NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-56675 - EKEN Video Doorbell T6 Wi-Fi Information Disclosure

CVE ID : CVE-2025-56675
Published : Sept. 30, 2025, 6:15 p.m. | 1 hour, 11 minutes ago
Description : The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-57254 - Karthikg1908 Hospital Management System (HMS) SQL Injection Vulnerability

CVE ID : CVE-2025-57254
Published : Sept. 30, 2025, 6:15 p.m. | 1 hour, 11 minutes ago
Description : An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execute arbitrary SQL queries via the username and password POST parameters. The application fails to properly sanitize input before embedding it into SQL queries, leading to unauthorized access or potential data breaches. This can result in privilege escalation, account takeover, or exposure of sensitive medical data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43827 - Liferay Portal Liferay DXP IDOR Audit Events Vulnerability

CVE ID : CVE-2025-43827
Published : Sept. 30, 2025, 6:57 p.m. | 29 minutes ago
Description : Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from one virtual instance to view the audit events from a different virtual instance via the _com_liferay_portal_security_audit_web_portlet_AuditPortlet_auditEventId parameter.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-56132 - LiquidFiles User Enumeration Vulnerability

CVE ID : CVE-2025-56132
Published : Sept. 30, 2025, 7:15 p.m. | 4 hours, 12 minutes ago
Description : LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based lockout mechanisms to mitigate brute-force attacks, user enumeration remains possible by default. In versions prior to 4.2, no such user-level protection is in place, only basic IP-based rate limiting is enforced. This IP-based protection can be bypassed by distributing requests across multiple IPs (e.g., rotating IP or proxies). Effectively bypassing both login and password reset security controls. Successful exploitation allows an attacker to enumerate valid email addresses registered for the application, increasing the risk of follow-up attacks such as password spraying.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-55017 - Corezoid OAuth2 Open Redirect Account Takeover

CVE ID : CVE-2024-55017
Published : Sept. 30, 2025, 8:15 p.m. | 3 hours, 12 minutes ago
Description : Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain unauthorized access to victim accounts.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10659 - MegaSys Enterprises Telenium Online Web Application OS Command Injection

CVE ID : CVE-2025-10659
Published : Sept. 30, 2025, 8:15 p.m. | 3 hours, 12 minutes ago
Description : The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs due to the insecure termination of a regular expression check within the endpoint. Because the input is not correctly validated or sanitized, an unauthenticated attacker can inject arbitrary operating system commands through a crafted HTTP request, leading to remote code execution on the server in the context of the web application service account.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36132 - IBM Planning Analytics Local cross-site scripting

CVE ID : CVE-2025-36132
Published : Sept. 30, 2025, 8:15 p.m. | 3 hours, 12 minutes ago
Description : IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36262 - IBM Planning Analytics Local information disclosure

CVE ID : CVE-2025-36262
Published : Sept. 30, 2025, 8:15 p.m. | 3 hours, 12 minutes ago
Description : IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-56392 - Syaqui Collegetivity IDOR Vulnerability

CVE ID : CVE-2025-56392
Published : Sept. 30, 2025, 8:15 p.m. | 3 hours, 12 minutes ago
Description : An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2022-40285 - Apache HTTP Server Command Injection Vulnerability

CVE ID : CVE-2022-40285
Published : Sept. 30, 2025, 9:15 p.m. | 2 hours, 12 minutes ago
Description : Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-13967. Reason: This record is a reservation duplicate of CVE-2024-13967. Notes: All CVE users should reference CVE-2024-13967 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43826 - Liferay Portal and DXP Stored XSS Vulnerability

CVE ID : CVE-2025-43826
Published : Sept. 30, 2025, 10:36 p.m. | 51 minutes ago
Description : Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via any rich text field in a web content article.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-55191 - Repository Credentials Race Condition Crashes Argo CD Server

CVE ID : CVE-2025-55191
Published : Sept. 30, 2025, 10:52 p.m. | 35 minutes ago
Description : Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. The vulnerability is located in numerous repository related handlers in the util/db/repository_secrets.go file. A valid API token with repositories resource permissions (create, update, or delete actions) is required to trigger the race condition. This vulnerability causes the entire Argo CD server to crash and become unavailable. Attackers can repeatedly and continuously trigger the race condition to maintain a denial-of-service state, disrupting all GitOps operations. This issue is fixed in versions 2.14.20, 3.2.0-rc2, 3.1.8 and 3.0.19.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-24525 - Keysight Ixia Vision Product Family Use of Hard-coded Cryptographic Key

CVE ID : CVE-2025-24525
Published : Sept. 30, 2025, 11:04 p.m. | 23 minutes ago
Description : Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device. Remediation is available in Version 6.9.1, released on September 23, 2025.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61792 - Quadient DS-700 iQ Kiosk Mode Race Condition Vulnerability

CVE ID : CVE-2025-61792
Published : Sept. 30, 2025, 11:15 p.m. | 2 hours, 26 minutes ago
Description : Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Question Mark button, the Help Button, the About button, and the Help Button, leading to a transition out of kiosk mode into local administrative access. NOTE: the reporter indicates that the "behavior was observed sporadically" during "limited time on the client site," making it not "possible to gain more information about the specific kiosk mode crashing issue," and the only conclusion was "there appears to be some form of race condition." Accordingly, there can be doubt that a reproducible cybersecurity vulnerability was identified; sporadic software crashes can also be caused by a hardware fault on a single device (for example, transient RAM errors). The reporter also describes a variety of other issues, including initial access via USB because of the absence of a "lock-pick resistant locking solution for the External Controller PC cabinet," which is not a cybersecurity vulnerability (section 4.1.5 of the CNA Operational Rules). Finally, it is unclear whether the device or OS configuration was inappropriate, given that the risks are typically limited to insider threats within the mail operations room of a large company.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61714 - Apache HTTP Server Unvalidated User Input

CVE ID : CVE-2025-61714
Published : Oct. 1, 2025, 3:15 a.m. | 2 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61715 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-61715
Published : Oct. 1, 2025, 3:15 a.m. | 2 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61716 - Apache HTTP Server Remote Code Execution

CVE ID : CVE-2025-61716
Published : Oct. 1, 2025, 3:15 a.m. | 2 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61717 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-61717
Published : Oct. 1, 2025, 3:15 a.m. | 2 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61718 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-61718
Published : Oct. 1, 2025, 3:15 a.m. | 2 hours, 24 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...