CVE tracker
281 subscribers
3.74K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-64683 - JetBrains Hub Unauthenticated Information Disclosure

CVE ID : CVE-2025-64683
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64684 - JetBrains YouTrack Information Disclosure Vulnerability

CVE ID : CVE-2025-64684
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64685 - In JetBrains YouTrack before 2025.3.104432 missing

CVE ID : CVE-2025-64685
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64686 - In JetBrains YouTrack before 2025.3.104432 missing

CVE ID : CVE-2025-64686
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 missing user principal cleanup led to reuse of incorrect authorization context
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64687 - JetBrains YouTrack Unauthenticated Modify MCP Tool Logic Vulnerability

CVE ID : CVE-2025-64687
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 improper access control allowed modify MCP tool logic
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64688 - JetBrains YouTrack Unvalidated VCS URL Delegation Vulnerability

CVE ID : CVE-2025-64688
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 missing VCS URL validation allowed delegation to unauthorized repositories from the Junie widget
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64689 - JetBrains YouTrack Junie Token Exposure

CVE ID : CVE-2025-64689
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-64690 - JetBrains YouTrack Junie Configuration Insecure Access Vulnerability

CVE ID : CVE-2025-64690
Published : Nov. 10, 2025, 2:15 p.m. | 2 hours, 25 minutes ago
Description : In JetBrains YouTrack before 2025.3.104432 insecure Junie configuration could lead to data exposure and unauthorized changes
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12480 - Triofox Improper Access Control

CVE ID : CVE-2025-12480
Published : Nov. 10, 2025, 3:15 p.m. | 1 hour, 25 minutes ago
Description : Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63709 - SourceCodester Simple To-Do List System XSS

CVE ID : CVE-2025-63709
Published : Nov. 10, 2025, 3:15 p.m. | 1 hour, 25 minutes ago
Description : A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript that is not correctly sanitized or encoded on output. The injected script is stored and later rendered in the browser of any user who views the task, allowing execution of arbitrary script in the context of the victim's browser.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63710 - SourceCodester Simple Public Chat Room CSRF

CVE ID : CVE-2025-63710
Published : Nov. 10, 2025, 3:15 p.m. | 1 hour, 25 minutes ago
Description : The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by an authenticated user, will automatically submit a forged POST request to the vulnerable endpoint. This request will be executed with the victim's privileges, allowing the attacker to perform unauthorized actions on their behalf, such as sending arbitrary messages in any chat room.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63711 - SourceCodester Client Database Management System CSRF Vulnerability

CVE ID : CVE-2025-63711
Published : Nov. 10, 2025, 3:15 p.m. | 1 hour, 25 minutes ago
Description : A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST requests containing a user_id parameter and does not enforce request origin or anti-CSRF tokens. Because the endpoint lacks proper authentication/authorization checks and CSRF protections, a remote attacker can craft a malicious page that triggers deletion when visited by an authenticated admin, resulting in arbitrary removal of user accounts.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63712 - SourceCodester Product Expiry Management System CSRF Vulnerability

CVE ID : CVE-2025-63712
Published : Nov. 10, 2025, 3:15 p.m. | 1 hour, 25 minutes ago
Description : Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-8768 - Apache Web Server Authentication Bypass

CVE ID : CVE-2025-8768
Published : Nov. 10, 2025, 3:15 p.m. | 1 hour, 25 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12020. Reason: This candidate is a reservation duplicate of CVE-2025-12020. Notes: All CVE users should reference CVE-2025-12020 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46430 - Dell Display and Peripheral Manager Execution with Unnecessary Privileges Vulnerability

CVE ID : CVE-2025-46430
Published : Nov. 10, 2025, 4:15 p.m. | 25 minutes ago
Description : Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulnerability in the Installer. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63152 - Tenda AX3 V16.03.12.10_CN was discovered to contai

CVE ID : CVE-2025-63152
Published : Nov. 10, 2025, 4:15 p.m. | 25 minutes ago
Description : Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63153 - TOTOLink A7000R V9.1.0u.6115_B20201022 was discove

CVE ID : CVE-2025-63153
Published : Nov. 10, 2025, 4:15 p.m. | 25 minutes ago
Description : TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63154 - TOTOLink A7000R Stack Overflow Denial of Service

CVE ID : CVE-2025-63154
Published : Nov. 10, 2025, 4:15 p.m. | 25 minutes ago
Description : TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12433 - Google Chrome V8 Out-of-Bounds Memory Access Vulnerability

CVE ID : CVE-2025-12433
Published : Nov. 10, 2025, 8:15 p.m. | 26 minutes ago
Description : Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12434 - Google Chrome UI Spoofing Vulnerability

CVE ID : CVE-2025-12434
Published : Nov. 10, 2025, 8:15 p.m. | 26 minutes ago
Description : Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12435 - Google Chrome Android UI Spoofing Vulnerability

CVE ID : CVE-2025-12435
Published : Nov. 10, 2025, 8:15 p.m. | 26 minutes ago
Description : Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...