CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-12245 - chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation

CVE ID : CVE-2025-12245
Published : Oct. 27, 2025, 8:15 a.m. | 1 hour, 36 minutes ago
Description : A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12246 - chatwoot Admin IframeLoader.vue cross site scripting

CVE ID : CVE-2025-12246
Published : Oct. 27, 2025, 8:15 a.m. | 1 hour, 36 minutes ago
Description : A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin Interface. The manipulation of the argument Link results in cross site scripting. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12247 - Hasleo Backup Suite HasleoImageMountService/HasleoBackupSuiteService unquoted search path

CVE ID : CVE-2025-12247
Published : Oct. 27, 2025, 8:15 a.m. | 1 hour, 36 minutes ago
Description : A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12248 - CLTPHP search.html sql injection

CVE ID : CVE-2025-12248
Published : Oct. 27, 2025, 8:15 a.m. | 1 hour, 36 minutes ago
Description : A security vulnerability has been detected in CLTPHP 3.0. The affected element is an unknown function of the file /home/search.html. Such manipulation of the argument keyword leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12249 - Axosoft Scrum and Bug Tracking Edit Ticket csv injection

CVE ID : CVE-2025-12249
Published : Oct. 27, 2025, 8:15 a.m. | 1 hour, 36 minutes ago
Description : A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing manipulation of the argument Title results in csv injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12080 - Intent Abuse in Google Messages for Wear OS for Silent Message Sending

CVE ID : CVE-2025-12080
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes is incorrectly implemented. Due to this misconfiguration, an attacker capable of invoking an Android intent can exploit this vulnerability to send messages on the user’s behalf to arbitrary receivers without requiring any further user interaction or specific permissions. This allows for the silent and unauthorized transmission of messages from a compromised Wear OS device.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12250 - OpenWGA TMLScript API WGA.File path traversal

CVE ID : CVE-2025-12250
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A flaw has been found in OpenWGA 7.11.12 Build 737. This affects an unknown function of the file WGA.File of the component TMLScript API. Executing manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12251 - OpenWGA Admin UI cross site scripting

CVE ID : CVE-2025-12251
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12252 - code-projects Online Event Judging System action.php sql injection

CVE ID : CVE-2025-12252
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A vulnerability was found in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /ajax/action.php. The manipulation of the argument content results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12253 - AMTT Hotel Broadband Operation System get_expiredtime.php sql injection

CVE ID : CVE-2025-12253
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php. This manipulation of the argument uid causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12254 - code-projects Online Event Judging System add_judge.php sql injection

CVE ID : CVE-2025-12254
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown functionality of the file /add_judge.php. Such manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12255 - code-projects Online Event Judging System add_contestant.php sql injection

CVE ID : CVE-2025-12255
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of the file /add_contestant.php. Performing manipulation of the argument fullname results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46582 - Private Key Disclosure Vulnerability in ZTE ZXMP M721 Product

CVE ID : CVE-2025-46582
Published : Oct. 27, 2025, 9:15 a.m. | 36 minutes ago
Description : A private key disclosure vulnerability exists in ZTE's ZXMP M721 product. A low-privileged user can bypass authorization checks to view the device's communication private key, resulting in key exposure and impacting communication security.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46583 - DOS Vulnerability in ZTE MC889A Pro product

CVE ID : CVE-2025-46583
Published : Oct. 27, 2025, 9:23 a.m. | 28 minutes ago
Description : There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12256 - code-projects Online Event Judging System edit_contestant.php sql injection

CVE ID : CVE-2025-12256
Published : Oct. 27, 2025, 9:32 a.m. | 20 minutes ago
Description : A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /edit_contestant.php. Executing manipulation of the argument contestant_id can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12257 - SourceCodester Online Student Result System view_result.php sql injection

CVE ID : CVE-2025-12257
Published : Oct. 27, 2025, 9:32 a.m. | 20 minutes ago
Description : A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file /view_result.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12258 - TOTOLINK A3300R POST Parameter cstecgi.cg setOpModeCfg stack-based overflow

CVE ID : CVE-2025-12258
Published : Oct. 27, 2025, 9:32 a.m. | 20 minutes ago
Description : A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the component POST Parameter Handler. The manipulation of the argument opmode results in stack-based buffer overflow. The attack may be performed from remote.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59459 - Denial-of-service (DoS) via resource consumption

CVE ID : CVE-2025-59459
Published : Oct. 27, 2025, 11:15 a.m. | 2 hours, 36 minutes ago
Description : An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59460 - Unsecure access configuration

CVE ID : CVE-2025-59460
Published : Oct. 27, 2025, 11:15 a.m. | 2 hours, 36 minutes ago
Description : The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59461 - API does not require authentication

CVE ID : CVE-2025-59461
Published : Oct. 27, 2025, 11:15 a.m. | 2 hours, 36 minutes ago
Description : A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59462 - Denial-of-service (DoS) via delayed or missing client response

CVE ID : CVE-2025-59462
Published : Oct. 27, 2025, 11:15 a.m. | 2 hours, 36 minutes ago
Description : An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...