CVE tracker
249 subscribers
3.29K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-48983 - Veeam Backup & Replication Mount Service Authenticated RCE Vulnerability

CVE ID : CVE-2025-48983
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48984 - VMware vSphere Backup Server Remote Code Execution Vulnerability

CVE ID : CVE-2025-48984
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52663 - Ubiquiti UniFi Talk Debugging Functionality Unintentional Enablement

CVE ID : CVE-2025-52663
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Products: UniFi Talk Touch (Version 1.21.16 and earlier) UniFi Talk Touch Max (Version 2.21.22 and earlier) UniFi Talk G3 Phones (Version 3.21.26 and earlier) Mitigation: Update the UniFi Talk Touch to Version 1.21.17 or later. Update the UniFi Talk Touch Max to Version 2.21.23 or later. Update the UniFi Talk G3 Phones to Version 3.21.27 or later.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52664 - Revive Adserver SQL Injection Vulnerability

CVE ID : CVE-2025-52664
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52665 - "Ubiquiti UniFi Access Unauthenticated API Exposure"

CVE ID : CVE-2025-52665
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6176 - Brotli decompression bomb DoS in scrapy/scrapy

CVE ID : CVE-2025-6176
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8849 - Denial of Service in danny-avila/librechat

CVE ID : CVE-2025-8849
Published : Oct. 31, 2025, 12:15 a.m. | 1 hour, 1 minute ago
Description : LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23050 - Qt QLowEnergyController Bluetooth ATT Command Handling Vulnerability

CVE ID : CVE-2025-23050
Published : Oct. 31, 2025, 2:15 a.m. | 3 hours, 3 minutes ago
Description : QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11806 - Qzzr Shortcode Plugin <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVE ID : CVE-2025-11806
Published : Oct. 31, 2025, 3:15 a.m. | 2 hours, 3 minutes ago
Description : The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'quiz' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11975 - FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation

CVE ID : CVE-2025-11975
Published : Oct. 31, 2025, 3:15 a.m. | 2 hours, 3 minutes ago
Description : The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_changes() function in all versions up to, and including, 1.1.23.0. This makes it possible for unauthenticated attackers to add and edit sync rules.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11191 - RealPress < 1.1.0 - Unauthenticated Content Creation/Email Sending via REST

CVE ID : CVE-2025-11191
Published : Oct. 31, 2025, 6:15 a.m. | 3 hours, 4 minutes ago
Description : The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-54763 - "Century Systems Co., Ltd. FutureNet MA and IP-K series OS Command Injection Vulnerability"

CVE ID : CVE-2025-54763
Published : Oct. 31, 2025, 6:15 a.m. | 3 hours, 4 minutes ago
Description : FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-58152 - Century Systems Co., Ltd. FutureNet MA and IP-K series Information Disclosure

CVE ID : CVE-2025-58152
Published : Oct. 31, 2025, 6:15 a.m. | 3 hours, 4 minutes ago
Description : FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5397 - Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass

CVE ID : CVE-2025-5397
Published : Oct. 31, 2025, 7:15 a.m. | 2 hours, 4 minutes ago
Description : The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackers to bypass standard authentication and access administrative user accounts. Please note social login needs to be enabled in order for a site to be impacted by this vulnerability.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63675 - Cryptidy Deserialization Vulnerability (Code Execution)

CVE ID : CVE-2025-63675
Published : Oct. 31, 2025, 7:15 a.m. | 2 hours, 4 minutes ago
Description : cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-7846 - WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function

CVE ID : CVE-2025-7846
Published : Oct. 31, 2025, 7:15 a.m. | 2 hours, 4 minutes ago
Description : The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8489 - King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation

CVE ID : CVE-2025-8489
Published : Oct. 31, 2025, 7:15 a.m. | 2 hours, 4 minutes ago
Description : The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10897 - WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

CVE ID : CVE-2025-10897
Published : Oct. 31, 2025, 8:15 a.m. | 1 hour, 4 minutes ago
Description : The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-6520 - SQLi in Abis Technology's BAPSIS

CVE ID : CVE-2025-6520
Published : Oct. 31, 2025, 8:15 a.m. | 1 hour, 4 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection.This issue affects BAPSIS: before 202510271606.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8385 - Zombify <= 1.7.5 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read

CVE ID : CVE-2025-8385
Published : Oct. 31, 2025, 8:15 a.m. | 1 hour, 4 minutes ago
Description : The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input validation in the zf_get_file_by_url function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrary files on the server, including sensitive system files like /etc/passwd, via a forged request. It's worth noting that successfully exploiting this vulnerability relies on a race condition as the file generated will be deleted immediately.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12175 - The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure

CVE ID : CVE-2025-12175
Published : Oct. 31, 2025, 8:25 a.m. | 53 minutes ago
Description : The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...