CVE tracker
280 subscribers
3.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-62606 - my little forum vulnerable to SQL Injection in Bookmark Reordering via bookmarks parameter

CVE ID : CVE-2025-62606
Published : Oct. 22, 2025, 3:16 p.m. | 1 hour, 50 minutes ago
Description : my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23299 - NVIDIA Bluefield ConnectX Remote Code Execution Vulnerability

CVE ID : CVE-2025-23299
Published : Oct. 22, 2025, 4:15 p.m. | 51 minutes ago
Description : NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-40778 - Cache poisoning attacks with unsolicited RRs

CVE ID : CVE-2025-40778
Published : Oct. 22, 2025, 4:15 p.m. | 51 minutes ago
Description : Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-40780 - Cache poisoning due to weak PRNG

CVE ID : CVE-2025-40780
Published : Oct. 22, 2025, 4:15 p.m. | 51 minutes ago
Description : In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60333 - TOTOLINK N600R Stack Overflow Vulnerability

CVE ID : CVE-2025-60333
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60334 - TOTOLINK N600R Stack Overflow Denial of Service

CVE ID : CVE-2025-60334
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60335 - TOTOLINK N600R Denial of Service (DoS) NULL Pointer Dereference

CVE ID : CVE-2025-60335
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60338 - Tenda AC6 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-60338
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-62607 - Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

CVE ID : CVE-2025-62607
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker could access this page to view the Service Now public instance name e.g. companyname.service-now.com. This is considered low-value information. This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page. This issue has been patched in version 3.10.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-62659 - The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors

CVE ID : CVE-2025-62659
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki CookieConsent extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki CookieConsent extension: from v0.1.0 before v2.0.0.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8677 - Resource exhaustion via malformed DNSKEY handling

CVE ID : CVE-2025-8677
Published : Oct. 22, 2025, 4:15 p.m. | 50 minutes ago
Description : Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22175 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22175
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22177 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22177
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22168 - Atlassian Jira Align Authorization Bypass

CVE ID : CVE-2025-22168
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22171 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22171
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22176 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22176
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22172 - "Atlassian Jira Align Authorization Bypass"

CVE ID : CVE-2025-22172
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22174 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22174
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22170 - Jira Align Privilege Escalation Authorization Bypass

CVE ID : CVE-2025-22170
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22173 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22173
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22169 - Jira Align Authorization Bypass

CVE ID : CVE-2025-22169
Published : Oct. 22, 2025, 4:30 p.m. | 36 minutes ago
Description : Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...