CVE tracker
312 subscribers
4.41K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-11897 - The7 — Ultimate WordPress & WooCommerce Theme <= 12.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css'

CVE ID : CVE-2025-11897
Published : Oct. 25, 2025, 1:15 p.m. | 2 hours, 15 minutes ago
Description : The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ the7_fancy_title_css’ parameter in all versions up to, and including, 12.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12216 - Malicious / Malformed App can be Installed but not Uninstalled

CVE ID : CVE-2025-12216
Published : Oct. 25, 2025, 4:15 p.m. | 3 hours, 16 minutes ago
Description : Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12217 - SNMP Default Community String (public)

CVE ID : CVE-2025-12217
Published : Oct. 25, 2025, 4:15 p.m. | 3 hours, 16 minutes ago
Description : SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12218 - Weak Default Credentials

CVE ID : CVE-2025-12218
Published : Oct. 25, 2025, 4:15 p.m. | 3 hours, 16 minutes ago
Description : Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12219 - Vulnerable Components in Azure Access OS

CVE ID : CVE-2025-12219
Published : Oct. 25, 2025, 4:15 p.m. | 3 hours, 16 minutes ago
Description : Vulnerable Components in Azure Access OS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12220 - Busybox 1.31.1 - Multiple Known Vulnerabilities

CVE ID : CVE-2025-12220
Published : Oct. 25, 2025, 4:15 p.m. | 3 hours, 16 minutes ago
Description : Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12221 - CSRF Token not Properly Implemented

CVE ID : CVE-2025-12221
Published : Oct. 25, 2025, 4:15 p.m. | 3 hours, 16 minutes ago
Description : Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-55757 - Extension - virtuemart.net - XSS in VirtueMart component 1.0.0 - 4.4.10 for Joomla

CVE ID : CVE-2025-55757
Published : Oct. 25, 2025, 7:15 p.m. | 16 minutes ago
Description : A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8709 - SQL Injection in langchain-ai/langchain

CVE ID : CVE-2025-8709
Published : Oct. 26, 2025, 6:15 a.m. | 3 hours, 24 minutes ago
Description : A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers to inject arbitrary SQL, leading to unauthorized access to all documents, data exfiltration of sensitive fields such as passwords and API keys, and a complete bypass of application-level security filters.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12275 - Mail Configuration File Manipulation + Command Execution

CVE ID : CVE-2025-12275
Published : Oct. 26, 2025, 5:15 p.m. | 32 minutes ago
Description : Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12278 - Logout Functionality not Working

CVE ID : CVE-2025-12278
Published : Oct. 26, 2025, 5:15 p.m. | 32 minutes ago
Description : Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12284 - Lack of Input Validation

CVE ID : CVE-2025-12284
Published : Oct. 26, 2025, 5:15 p.m. | 32 minutes ago
Description : Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12285 - Missing Initial Password Change

CVE ID : CVE-2025-12285
Published : Oct. 26, 2025, 5:15 p.m. | 32 minutes ago
Description : Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10497 - Allocation of Resources Without Limits or Throttling in GitLab

CVE ID : CVE-2025-10497
Published : Oct. 27, 2025, 12:15 a.m. | 1 hour, 36 minutes ago
Description : GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11447 - Allocation of Resources Without Limits or Throttling in GitLab

CVE ID : CVE-2025-11447
Published : Oct. 27, 2025, 12:15 a.m. | 1 hour, 36 minutes ago
Description : GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11971 - Incorrect Authorization in GitLab

CVE ID : CVE-2025-11971
Published : Oct. 27, 2025, 12:15 a.m. | 1 hour, 36 minutes ago
Description : GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11974 - Allocation of Resources Without Limits or Throttling in GitLab

CVE ID : CVE-2025-11974
Published : Oct. 27, 2025, 12:15 a.m. | 1 hour, 36 minutes ago
Description : GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11989 - Missing Authorization in GitLab

CVE ID : CVE-2025-11989
Published : Oct. 27, 2025, 12:15 a.m. | 1 hour, 36 minutes ago
Description : GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6601 - Business Logic Errors in GitLab

CVE ID : CVE-2025-6601
Published : Oct. 27, 2025, 12:15 a.m. | 1 hour, 36 minutes ago
Description : GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12198 - dnsmasq Config File util.c parse_hex heap-based overflow

CVE ID : CVE-2025-12198
Published : Oct. 27, 2025, 1:15 a.m. | 36 minutes ago
Description : A vulnerability has been found in dnsmasq up to 2.73rc6. Affected is the function parse_hex of the file src/util.c of the component Config File Handler. The manipulation of the argument i leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12199 - dnsmasq Config File network.c check_servers null pointer dereference

CVE ID : CVE-2025-12199
Published : Oct. 27, 2025, 1:15 a.m. | 36 minutes ago
Description : A vulnerability was found in dnsmasq up to 2.73rc6. Affected by this vulnerability is the function check_servers of the file src/network.c of the component Config File Handler. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...