CVE tracker
308 subscribers
4.38K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-15168 - itsourcecode Student Management System statistical.php sql injection

CVE ID : CVE-2025-15168
Published : Dec. 29, 2025, 3:15 a.m. | 2 hours, 38 minutes ago
Description : A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52691 - Upload Arbitrary Files

CVE ID : CVE-2025-52691
Published : Dec. 29, 2025, 3:15 a.m. | 2 hours, 38 minutes ago
Description : Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15169 - BiggiDroid Simple PHP CMS editsite.php sql injection

CVE ID : CVE-2025-15169
Published : Dec. 29, 2025, 4:15 a.m. | 1 hour, 37 minutes ago
Description : A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected by this issue is some unknown functionality of the file /admin/editsite.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15170 - Advaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting

CVE ID : CVE-2025-15170
Published : Dec. 29, 2025, 4:15 a.m. | 1 hour, 37 minutes ago
Description : A security vulnerability has been detected in Advaya Softech GEMS ERP Portal up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of the component Error Message Handler. The manipulation of the argument Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15068 - Account Takeover in Gmission Web FAX

CVE ID : CVE-2025-15068
Published : Dec. 29, 2025, 5:05 a.m. | 48 minutes ago
Description : Missing Authorization vulnerability in Gmission Web Fax allows Privilege Abuse, Session Credential Falsification through Manipulation.This issue affects Web Fax: from 3.0 before 4.0.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15069 - Privilege Escalation in Gmission Web FAX

CVE ID : CVE-2025-15069
Published : Dec. 29, 2025, 5:05 a.m. | 47 minutes ago
Description : Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3.0 before 4.0.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15070 - Data Exposure in Gmission Web FAX

CVE ID : CVE-2025-15070
Published : Dec. 29, 2025, 5:06 a.m. | 47 minutes ago
Description : Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse.This issue affects Web Fax: from 3.0 before 4.0.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15171 - SohuTV CacheCloud ServerController.java index cross site scripting

CVE ID : CVE-2025-15171
Published : Dec. 29, 2025, 5:15 a.m. | 37 minutes ago
Description : A vulnerability was identified in SohuTV CacheCloud up to 3.2.0. This affects the function index of the file src/main/java/com/sohu/cache/web/controller/ServerController.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15172 - SohuTV CacheCloud RedisConfigTemplateController.java preview cross site scripting

CVE ID : CVE-2025-15172
Published : Dec. 29, 2025, 5:15 a.m. | 37 minutes ago
Description : A security flaw has been discovered in SohuTV CacheCloud up to 3.2.0. This impacts the function preview of the file src/main/java/com/sohu/cache/web/controller/RedisConfigTemplateController.java. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be exploited. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15173 - SohuTV CacheCloud InstanceController.java advancedAnalysis cross site scripting

CVE ID : CVE-2025-15173
Published : Dec. 29, 2025, 5:16 a.m. | 37 minutes ago
Description : A weakness has been identified in SohuTV CacheCloud up to 3.2.0. Affected is the function advancedAnalysis of the file src/main/java/com/sohu/cache/web/controller/InstanceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15174 - SohuTV CacheCloud AppManageController.java doAppAuditList cross site scripting

CVE ID : CVE-2025-15174
Published : Dec. 29, 2025, 5:32 a.m. | 21 minutes ago
Description : A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this vulnerability is the function doAppAuditList of the file src/main/java/com/sohu/cache/web/controller/AppManageController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-13417 - Plugin Organizer < 10.2.4 - Subscriber+ SQLi

CVE ID : CVE-2025-13417
Published : Dec. 29, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-13958 - YaMaps < 0.6.40 - Contributor+ Stored XSS

CVE ID : CVE-2025-13958
Published : Dec. 29, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : The YaMaps for WordPress Plugin WordPress plugin before 0.6.40 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15175 - SohuTV CacheCloud AppController.java appCommandAnalysis cross site scripting

CVE ID : CVE-2025-15175
Published : Dec. 29, 2025, 6:15 a.m. | 3 hours, 40 minutes ago
Description : A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doAppList/appCommandAnalysis of the file src/main/java/com/sohu/cache/web/controller/AppController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15176 - Open5GS PFCP Session Establishment Request rule-match.c ogs_pfcp_pdr_rule_find_by_packet assertion

CVE ID : CVE-2025-15176
Published : Dec. 29, 2025, 7:15 a.m. | 2 hours, 40 minutes ago
Description : A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing manipulation can lead to reachable assertion. It is possible to launch the attack remotely. The exploit has been published and may be used. This patch is called b72d8349980076e2c033c8324f07747a86eea4f8. Applying a patch is advised to resolve this issue.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15177 - Tenda WH450 HTTP Request SetIpBind stack-based overflow

CVE ID : CVE-2025-15177
Published : Dec. 29, 2025, 7:15 a.m. | 2 hours, 40 minutes ago
Description : A vulnerability has been found in Tenda WH450 1.0.0.18. This vulnerability affects unknown code of the file /goform/SetIpBind of the component HTTP Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15225 - Sunnet|WMPro - Arbitrary File Read

CVE ID : CVE-2025-15225
Published : Dec. 29, 2025, 7:15 a.m. | 2 hours, 40 minutes ago
Description : WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15226 - Sunnet|WMPro - Arbitrary File Upload

CVE ID : CVE-2025-15226
Published : Dec. 29, 2025, 7:15 a.m. | 2 hours, 40 minutes ago
Description : WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15178 - Tenda WH450 HTTP Request VirtualSer stack-based overflow

CVE ID : CVE-2025-15178
Published : Dec. 29, 2025, 8:15 a.m. | 1 hour, 40 minutes ago
Description : A vulnerability was found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/VirtualSer of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15179 - Tenda WH450 qossetting stack-based overflow

CVE ID : CVE-2025-15179
Published : Dec. 29, 2025, 8:15 a.m. | 1 hour, 40 minutes ago
Description : A vulnerability was determined in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/qossetting. This manipulation of the argument page causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15227 - WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read

CVE ID : CVE-2025-15227
Published : Dec. 29, 2025, 8:15 a.m. | 1 hour, 40 minutes ago
Description : BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...