CVE tracker
233 subscribers
3.14K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-22195 - Apache Struts Command Injection Vulnerability

CVE ID : CVE-2025-22195
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22196 - Apache Struts Remote Code Execution Vulnerability

CVE ID : CVE-2025-22196
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22197 - Apache Struts Remote Code Execution Vulnerability

CVE ID : CVE-2025-22197
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22198 - Apache Struts Deserialization Remote Code Execution

CVE ID : CVE-2025-22198
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22199 - Apache Struts Remote Code Execution Vulnerability

CVE ID : CVE-2025-22199
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22200 - Apache HTTP Server SQL Injection

CVE ID : CVE-2025-22200
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22201 - VMware vCenter Server Remote Code Execution

CVE ID : CVE-2025-22201
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22202 - Apache HTTP Server Cross-Site Request Forgery

CVE ID : CVE-2025-22202
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22203 - Apache Struts Code Injection Vulnerability

CVE ID : CVE-2025-22203
Published : Jan. 1, 2026, 1:15 a.m. | 3 hours, 5 minutes ago
Description : Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-69413 - Gitea Authentication Information Disclosure

CVE ID : CVE-2025-69413
Published : Jan. 1, 2026, 5:16 a.m. | 3 hours, 6 minutes ago
Description : In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-13820 - Comments – wpDiscuz < 7.6.40 - Unauthenticated Account Takeover

CVE ID : CVE-2025-13820
Published : Jan. 1, 2026, 6:15 a.m. | 2 hours, 6 minutes ago
Description : The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11157 - Arbitrary Code Execution in feast-dev/feast

CVE ID : CVE-2025-11157
Published : Jan. 1, 2026, 7:16 a.m. | 1 hour, 6 minutes ago
Description : A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability arises from the use of `yaml.load(..., Loader=yaml.Loader)` to deserialize `/var/feast/feature_store.yaml` and `/var/feast/materialization_config.yaml`. This method allows for the instantiation of arbitrary Python objects, enabling an attacker with the ability to modify these YAML files to execute OS commands on the worker pod. This vulnerability can be exploited before the configuration is validated, potentially leading to cluster takeover, data poisoning, and supply-chain sabotage.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0544 - itsourcecode School Management System index.php sql injection

CVE ID : CVE-2026-0544
Published : Jan. 1, 2026, 9:15 a.m. | 3 hours, 8 minutes ago
Description : A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15404 - campcodes School File Management System save_file.php unrestricted upload

CVE ID : CVE-2025-15404
Published : Jan. 1, 2026, 2:16 p.m. | 2 hours, 9 minutes ago
Description : A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15405 - PHPEMS cross-site request forgery

CVE ID : CVE-2025-15405
Published : Jan. 1, 2026, 3:15 p.m. | 1 hour, 10 minutes ago
Description : A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-66023 - NanoMQ has Use-After-Free of malformed bridging message

CVE ID : CVE-2025-66023
Published : Jan. 1, 2026, 3:15 p.m. | 1 hour, 10 minutes ago
Description : NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability is triggered when NanoMQ acts as a bridge connecting to a remote MQTT broker. A malicious remote broker can trigger a crash (Denial of Service) or potential memory corruption by accepting the connection and immediately sending a malformed packet sequence. Version 0.34.5 contains a patch. The patch enforces stricter protocol adherence in the MQTT client SDK embedded in NanoMQ. Specifically, it ensures that CONNACK is always the first packet processed in the line. This prevents the state confusion that led to the Heap-Use-After-Free (UAF) when a malicious server sent a malformed packet sequence immediately after connection establishment. As a workaround, validate the remote broker before bridging.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14428 - My Sticky Elements <= 2.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk Lead Deletion

CVE ID : CVE-2025-14428
Published : Jan. 1, 2026, 5:15 p.m. | 3 hours, 10 minutes ago
Description : The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all contact form leads stored by the plugin.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14627 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink Bypass

CVE ID : CVE-2025-14627
Published : Jan. 1, 2026, 5:15 p.m. | 3 hours, 10 minutes ago
Description : The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial URL is validated using `wp_http_validate_url()`, when a Bitly shortlink is detected, the `unshorten_bitly_url()` function follows redirects to the final destination URL without re-validating it. This makes it possible for authenticated attackers with Contributor-level access or higher to make the server perform HTTP requests to arbitrary internal endpoints, including localhost, private IP ranges, and cloud metadata services (e.g., 169.254.169.254), potentially exposing sensitive internal data.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-15406 - PHPGurukul Online Course Registration authorization

CVE ID : CVE-2025-15406
Published : Jan. 1, 2026, 5:15 p.m. | 3 hours, 10 minutes ago
Description : A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47411 - Apache StreamPipes: Leverage of User ID for Privilege Escalation

CVE ID : CVE-2025-47411
Published : Jan. 1, 2026, 5:15 p.m. | 3 hours, 10 minutes ago
Description : A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulnerability allows an attacker to gain administrative control over the application by manipulating JWT tokens, which can lead to data tampering, unauthorized access and other security issues. This issue affects Apache StreamPipes: through 0.97.0. Users are recommended to upgrade to version 0.98.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-48768 - Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal

CVE ID : CVE-2025-48768
Published : Jan. 1, 2026, 5:15 p.m. | 3 hours, 10 minutes ago
Description : Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the target architecture), or in general, a Denial of Service. This issue affects Apache NuttX RTOS: from 10.0.0 before 12.10.0. Users of filesystem based services with write access that were exposed over the network (i.e. FTP) are affected and recommended to upgrade to version 12.10.0 that fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...