CVE-2025-1619

CVE-2025-1619

Título es
CVE-2025-1619

Dom, 16/03/2025 – 06:15

Gravedad 2.0 Txt
Pendiente de análisis

Título en

CVE-2025-1619

Descripción en
The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

16/03/2025

16/03/2025

Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis

Referencias


  • https://wpscan.com/vulnerability/ae9bc19d-1634-4501-a258-8c56b2afee88/
  • Enviar en el boletín
    Off

    CVE-2024-13602

    CVE-2024-13602

    Título es
    CVE-2024-13602

    Dom, 16/03/2025 – 06:15

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2024-13602

    Descripción en
    The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    16/03/2025

    16/03/2025

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    Pendiente de análisis

    Referencias


  • https://wpscan.com/vulnerability/05d5010b-94eb-4fd3-b962-e2a16c032b71/
  • Enviar en el boletín
    Off

    CVE-2025-1624

    CVE-2025-1624

    Título es
    CVE-2025-1624

    Dom, 16/03/2025 – 06:15

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2025-1624

    Descripción en
    The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    16/03/2025

    16/03/2025

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    Pendiente de análisis

    Referencias


  • https://wpscan.com/vulnerability/2f4a402a-97f6-4638-9ce0-456ccd5606e9/
  • Enviar en el boletín
    Off

    CVE-2025-1623

    CVE-2025-1623

    Título es
    CVE-2025-1623

    Dom, 16/03/2025 – 06:15

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2025-1623

    Descripción en
    The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    16/03/2025

    16/03/2025

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    Pendiente de análisis

    Referencias


  • https://wpscan.com/vulnerability/40288fa0-50c6-4e13-9b92-968b060d3bf5/
  • Enviar en el boletín
    Off

    CVE-2025-2335

    CVE-2025-2335

    Título es
    CVE-2025-2335

    Dom, 16/03/2025 – 03:15

    Tipo
    CWE-79

    Gravedad v2.0
    4.00

    Gravedad 2.0 Txt
    MEDIUM

    Título en

    CVE-2025-2335

    Descripción en
    A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknown code of the file /api/school/registerSchool of the component API Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    16/03/2025

    16/03/2025

    Vector CVSS:4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

    Vector CVSS:3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

    Vector CVSS:2.0
    AV:N/AC:L/Au:S/C:N/I:P/A:N

    Gravedad 4.0
    5.10

    Gravedad 4.0 txt
    MEDIUM

    Gravedad 3.1 (CVSS 3.1 Base Score)
    3.50

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    LOW

    Referencias


  • https://github.com/yago3008/cves

  • https://vuldb.com/?ctiid_299800=

  • https://vuldb.com/?id_299800=

  • https://vuldb.com/?submit_509834=
  • Enviar en el boletín
    Off

    CVE-2025-30077

    CVE-2025-30077

    Título es
    CVE-2025-30077

    Dom, 16/03/2025 – 03:15

    Tipo
    CWE-129

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2025-30077

    Descripción en
    Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.

    16/03/2025

    16/03/2025

    Vector CVSS:3.1
    CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

    Gravedad 3.1 (CVSS 3.1 Base Score)
    6.20

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    MEDIUM

    Referencias


  • https://github.com/onosproject/onos-lib-go/issues/295
  • Enviar en el boletín
    Off

    CVE-2025-30076

    CVE-2025-30076

    Título es
    CVE-2025-30076

    Dom, 16/03/2025 – 03:15

    Tipo
    CWE-78

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2025-30076

    Descripción en
    Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.

    16/03/2025

    16/03/2025

    Vector CVSS:3.1
    CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

    Gravedad 3.1 (CVSS 3.1 Base Score)
    7.70

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    HIGH

    Referencias


  • https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=39170

  • https://github.com/gl0wyy/koha-task-scheduler-rce
  • Enviar en el boletín
    Off

    CVE-2025-30074

    CVE-2025-30074

    Título es
    CVE-2025-30074

    Dom, 16/03/2025 – 03:15

    Tipo
    CWE-863

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2025-30074

    Descripción en
    Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine.

    16/03/2025

    16/03/2025

    Vector CVSS:3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

    Gravedad 3.1 (CVSS 3.1 Base Score)
    7.80

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    HIGH

    Referencias


  • https://kb.parallels.com/en/130944
  • Enviar en el boletín
    Off

    CVE-2024-58103

    CVE-2024-58103

    Título es
    CVE-2024-58103

    Dom, 16/03/2025 – 04:15

    Tipo
    CWE-674

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2024-58103

    Descripción en
    Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.

    16/03/2025

    16/03/2025

    Vector CVSS:3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

    Gravedad 3.1 (CVSS 3.1 Base Score)
    5.80

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    MEDIUM

    Referencias


  • https://github.com/square/wire/commit/b90e60c09befaff836a2fc2ee4d678451b2ec75d

  • https://github.com/square/wire/compare/5.1.0…5.2.0
  • Enviar en el boletín
    Off

    CVE-2025-24856

    CVE-2025-24856

    Título es
    CVE-2025-24856

    Dom, 16/03/2025 – 04:15

    Tipo
    CWE-348

    Gravedad 2.0 Txt
    Pendiente de análisis

    Título en

    CVE-2025-24856

    Descripción en
    An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the following requirements are met: (1) an attacker can anticipate the e-mail address of the user, (2) an attacker can register a public frontend user account using that e-mail address before the user's first OIDC login, and (3) the IDP returns an email field containing the e-mail address of the user,

    16/03/2025

    16/03/2025

    Vector CVSS:3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

    Gravedad 3.1 (CVSS 3.1 Base Score)
    4.20

    Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
    MEDIUM

    Referencias


  • https://github.com/xperseguers/t3ext-oidc/commit/877e09f6faf4c87bbb41233112ec7e30d3c902b3

  • https://typo3.org/security/advisory/typo3-ext-sa-2025-001
  • Enviar en el boletín
    Off