CVE tracker
274 subscribers
3.52K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2024-45743 - Apache HTTP Server Cross-Site Scripting

CVE ID : CVE-2024-45743
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-53248 - Apache Struts Command Injection

CVE ID : CVE-2024-53248
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-53249 - Apache HTTP Server Cross-Site Scripting

CVE ID : CVE-2024-53249
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-53250 - Apache HTTP Server Cross-Site Scripting

CVE ID : CVE-2024-53250
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-53251 - Apache HTTP Server Remote Buffer Overflow

CVE ID : CVE-2024-53251
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-53252 - Apache HTTP Server Remote Code Execution

CVE ID : CVE-2024-53252
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-13335 - Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab

CVE ID : CVE-2025-13335
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4763 - XSS in Aida Computer's Hotspot

CVE ID : CVE-2025-4763
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows Reflected XSS.This issue affects Hotel Guest Hotspot: through 22012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4764 - SQLi in Aida Computer's Hotspot

CVE ID : CVE-2025-4764
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hotspot allows SQL Injection.This issue affects Hotel Guest Hotspot: through 22012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1225 - Conditional processing of logback.xml configuration file, in conjuction with Spring Framework and Janino

CVE ID : CVE-2026-1225
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.
Severity: 1.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1332 - HAMASTAR Technology|MeetingHub - Missing Authentication

CVE ID : CVE-2026-1332
Published : Jan. 22, 2026, 10:16 a.m. | 50 minutes ago
Description : MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10024 - IDOR in EXERT Computer Technologies' Education Management System

CVE ID : CVE-2025-10024
Published : Jan. 22, 2026, 12:15 p.m. | 2 hours, 50 minutes ago
Description : Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Education Management System allows Parameter Injection.This issue affects Education Management System: through 23.09.2025.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67683 - Reflected XSS in Quick.Cart

CVE ID : CVE-2025-67683
Published : Jan. 22, 2026, 12:15 p.m. | 2 hours, 50 minutes ago
Description : Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim’s browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-67684 - Remote Code Execution via Local File Inclusion in Quick.Cart

CVE ID : CVE-2025-67684
Published : Jan. 22, 2026, 12:15 p.m. | 2 hours, 50 minutes ago
Description : Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents while only validating the filename extension. This allows an attacker to include and execute uploaded PHP code, resulting in Remote Code Execution on the server. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1324 - Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection

CVE ID : CVE-2026-1324
Published : Jan. 22, 2026, 1:02 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1325 - Sangfor Operation and Maintenance Security Management System edit_pwd_mall password recovery

CVE ID : CVE-2026-1325
Published : Jan. 22, 2026, 1:02 p.m. | 2 hours, 4 minutes ago
Description : A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10855 - IDOR in Solvera Software's Teknoera

CVE ID : CVE-2025-10855
Published : Jan. 22, 2026, 1:16 p.m. | 1 hour, 50 minutes ago
Description : Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identifiers.This issue affects Teknoera: through 01102025.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-10856 - Arbitrary File Upload in Solvera Software's Teknoera

CVE ID : CVE-2025-10856
Published : Jan. 22, 2026, 1:16 p.m. | 1 hour, 50 minutes ago
Description : Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection.This issue affects Teknoera: through 01102025.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-14295 - Automated Logic WebCTRL and Carrier i-Vu Session Fixation

CVE ID : CVE-2025-14295
Published : Jan. 22, 2026, 1:16 p.m. | 1 hour, 50 minutes ago
Description : Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them subject to password reuse attacks by malicious users.This issue affects WebCTRL: from 6.0 through 9.0; i-Vu: from 6.0 through 9.0.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-12738 - Enumeration of restricted property value

CVE ID : CVE-2025-12738
Published : Jan. 22, 2026, 1:29 p.m. | 1 hour, 37 minutes ago
Description : Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. The vulnerability allows attacker without read access to a property to infer information about its value by trying to enumerate all possible values through observing error messages of SET property. We recommend upgrading to 2025.11.2 or 5.26.17 and above, where the issues is fixed.
Severity: 1.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-1326 - Totolink NR1800X POST Request cstecgi.cgi setWanCfg command injection

CVE ID : CVE-2026-1326
Published : Jan. 22, 2026, 1:32 p.m. | 1 hour, 34 minutes ago
Description : A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...