CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-14247 - code-projects Simple Shopping Cart additems.php sql injection

CVE ID : CVE-2025-14247
Published : Dec. 8, 2025, 2:16 p.m. | 36 minutes ago
Description : A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument item_name can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14248 - code-projects Simple Shopping Cart adminlogin.php sql injection

CVE ID : CVE-2025-14248
Published : Dec. 8, 2025, 2:32 p.m. | 20 minutes ago
Description : A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14249 - code-projects Online Ordering System user_school.php sql injection

CVE ID : CVE-2025-14249
Published : Dec. 8, 2025, 3:15 p.m. | 1 hour, 38 minutes ago
Description : A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school.php. The manipulation of the argument product_id results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-60912 - phpIPAM CSRF Vulnerability in Database Export Functionality

CVE ID : CVE-2025-60912
Published : Dec. 8, 2025, 3:15 p.m. | 1 hour, 38 minutes ago
Description : phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14250 - code-projects Online Ordering System user_contact.php sql injection

CVE ID : CVE-2025-14250
Published : Dec. 8, 2025, 4:15 p.m. | 38 minutes ago
Description : A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14251 - code-projects Online Ordering System Admin Login admin sql injection

CVE ID : CVE-2025-14251
Published : Dec. 8, 2025, 4:15 p.m. | 38 minutes ago
Description : A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14271 - Rejected reason: This CVE ID has been withdrawn by

CVE ID : CVE-2025-14271
Published : Dec. 8, 2025, 4:15 p.m. | 38 minutes ago
Description : Rejected reason: This CVE ID has been withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61318 - Emlog Pro Directory Traversal Vulnerability

CVE ID : CVE-2025-61318
Published : Dec. 8, 2025, 4:15 p.m. | 37 minutes ago
Description : Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65796 - Usememos Memos Unauthenticated Delete Reaction Vulnerability

CVE ID : CVE-2025-65796
Published : Dec. 8, 2025, 4:15 p.m. | 37 minutes ago
Description : Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65798 - Apache Usememos Attachment Manipulation Vulnerability

CVE ID : CVE-2025-65798
Published : Dec. 8, 2025, 4:15 p.m. | 37 minutes ago
Description : Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48633 - Android Framework Information Disclosure Vulnerability - [Actively Exploited]

CVE ID : CVE-2025-48633
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48637 - Apache Memcached Out-of-Bounds Write Vulnerability

CVE ID : CVE-2025-48637
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48638 - Apache Pkvm Out-of-Bounds Write Privilege Escalation

CVE ID : CVE-2025-48638
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48639 - Android Android DefaultTransitionHandler Tapjacking Vulnerability

CVE ID : CVE-2025-48639
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-59391 - Apache libcoap Memory Disclosure Vulnerability

CVE ID : CVE-2025-59391
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-63721 - Apache Snakeyaml Deserialization Remote Code Execution

CVE ID : CVE-2025-63721
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component allowing attackers to achieve RCE and take over the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65363 - Ruijie APs Command Injection Vulnerability

CVE ID : CVE-2025-65363
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65795 - Usememos Memos Unauthenticated Account Creation Vulnerability

CVE ID : CVE-2025-65795
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65797 - Usememos Memos Identity Provider Access Control Vulnerability

CVE ID : CVE-2025-65797
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65799 - Usememos Memos Path Traversal Vulnerability

CVE ID : CVE-2025-65799
Published : Dec. 8, 2025, 5:16 p.m. | 3 hours, 40 minutes ago
Description : A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14258 - itsourcecode Student Management System newsubject.php sql injection

CVE ID : CVE-2025-14258
Published : Dec. 8, 2025, 6:15 p.m. | 2 hours, 40 minutes ago
Description : A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /newsubject.php. The manipulation of the argument sub leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...