CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-67825 - Nitro PDF Pro Certificate Display Inconsistency Vulnerability

CVE ID : CVE-2025-67825
Published : Jan. 8, 2026, 6:15 p.m. | 2 hours, 6 minutes ago
Description : An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information consistently reflects the verified certificate identity.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-68158 - Authlib: 1-click Account Takeover

CVE ID : CVE-2025-68158
Published : Jan. 8, 2026, 6:15 p.m. | 2 hours, 6 minutes ago
Description : Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prior, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid state (easily obtainable via an attacker-initiated authentication flow). When a cache is supplied to the OAuth client registry, FrameworkIntegration.set_state_data writes the entire state blob under _state_{app}_{state}, and get_state_data ignores the caller’s session altogether. This issue has been patched in version 1.6.6.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21896 - Kirby is missing permission checks in the content changes API

CVE ID : CVE-2026-21896
Published : Jan. 8, 2026, 6:15 p.m. | 2 hours, 6 minutes ago
Description : Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the update permission with the intent to prevent modifications to site content. This vulnerability does not affect those who have not altered the deviated from default user permissions. This issue has been patched in version 5.2.2.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22230 - OPEXUS eCASE Audit incorrect access control

CVE ID : CVE-2026-22230
Published : Jan. 8, 2026, 6:15 p.m. | 2 hours, 6 minutes ago
Description : OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. Fixed in eCASE Platform 11.14.1.0.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22231 - OPEXUS eCASE Audit Document Check Out stored XSS

CVE ID : CVE-2026-22231
Published : Jan. 8, 2026, 6:15 p.m. | 2 hours, 6 minutes ago
Description : OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is executed whenever another user views the Action History Log. Fixed in OPEXUS eCASE Platform 11.14.1.0.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22232 - OPEXUS eCASE Audit Project Setup stored XSS

CVE ID : CVE-2026-22232
Published : Jan. 8, 2026, 6:16 p.m. | 2 hours, 6 minutes ago
Description : OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22233 - OPEXUS eCASE Audit Project Cost stored XSS

CVE ID : CVE-2026-22233
Published : Jan. 8, 2026, 6:16 p.m. | 2 hours, 6 minutes ago
Description : OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22234 - OPEXUS eCasePortal unauthenticated IDOR

CVE ID : CVE-2026-22234
Published : Jan. 8, 2026, 6:16 p.m. | 2 hours, 6 minutes ago
Description : OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22235 - OPEXUS eComplaint IDOR

CVE ID : CVE-2026-22235
Published : Jan. 8, 2026, 6:16 p.m. | 2 hours, 6 minutes ago
Description : OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22587 - Ideagen DevonWay Reports page stored XSS

CVE ID : CVE-2026-22587
Published : Jan. 8, 2026, 6:16 p.m. | 2 hours, 6 minutes ago
Description : Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65518 - Plesk Obsidian Denial of Service

CVE ID : CVE-2025-65518
Published : Jan. 8, 2026, 7:15 p.m. | 1 hour, 6 minutes ago
Description : Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-65731 - D-Link Router DIR-605L UART Command Injection

CVE ID : CVE-2025-65731
Published : Jan. 8, 2026, 7:15 p.m. | 1 hour, 6 minutes ago
Description : An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access control.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67325 - QloApps Unrestricted File Upload Remote Code Execution

CVE ID : CVE-2025-67325
Published : Jan. 8, 2026, 7:15 p.m. | 1 hour, 6 minutes ago
Description : Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-21860 - Werkzeug safe_join() allows Windows special device names with compound extensions

CVE ID : CVE-2026-21860
Published : Jan. 8, 2026, 7:15 p.m. | 1 hour, 6 minutes ago
Description : Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. This issue has been patched in version 3.1.5.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22253 - Soft Serve is missing an authorization check in LFS lock deletion

CVE ID : CVE-2026-22253
Published : Jan. 8, 2026, 7:15 p.m. | 1 hour, 6 minutes ago
Description : Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22256 - Salvo is vulnerable to reflected XSS in the list_html function

CVE ID : CVE-2026-22256
Published : Jan. 8, 2026, 7:16 p.m. | 1 hour, 6 minutes ago
Description : Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected XSS using the fact that request path is decoded and normalized in the matching stage but not is inserted raw in the html view (current.path), the only constraint here is for the root path (eg. /files in the PoC example) to have a sub directory (e.g common ones styles/scripts/etc…) so that the matching return the list HTML page instead of the Not Found page. This issue has been patched in version 0.88.1.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22257 - Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names

CVE ID : CVE-2026-22257
Published : Jan. 8, 2026, 7:16 p.m. | 1 hour, 6 minutes ago
Description : Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue has been patched in version 0.88.1.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-0747 - TeamViewer Exposure of Sensitive Information in Devolutions Remote Desktop Manager

CVE ID : CVE-2026-0747
Published : Jan. 8, 2026, 7:55 p.m. | 26 minutes ago
Description : Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-66913 - JimuReport H2 JDBC Remote Code Execution Vulnerability

CVE ID : CVE-2025-66913
Published : Jan. 8, 2026, 8:15 p.m. | 4 hours, 7 minutes ago
Description : JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-66916 - RuoYi-Vue-Plus Snailjob QLExpress File Manipulation Vulnerability

CVE ID : CVE-2025-66916
Published : Jan. 8, 2026, 8:15 p.m. | 4 hours, 7 minutes ago
Description : The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-68715 - Panda Wireless PWRU0 Unauthenticated HTTP Endpoint Misconfiguration

CVE ID : CVE-2025-68715
Published : Jan. 8, 2026, 8:15 p.m. | 4 hours, 7 minutes ago
Description : An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege escalation and denial of service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...