CVE tracker
312 subscribers
4.42K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-21423 - Citrix Receiver Use-After-Free

CVE ID : CVE-2025-21423
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21425 - Citrix Systems HAB Process Memory Corruption Vulnerability

CVE ID : CVE-2025-21425
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption may occur due top improper access control in HAB process.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21428 - Aruba Wireless TSpec Memory Corruption Vulnerability

CVE ID : CVE-2025-21428
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21429 - Cisco Wireless STA Memory Corruption Vulnerability (Buffer Overflow)

CVE ID : CVE-2025-21429
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21430 - Cisco Wireless Router Denial of Service

CVE ID : CVE-2025-21430
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21431 - VMware Guest VM Information Disclosure

CVE ID : CVE-2025-21431
Published : April 7, 2025, 11:15 a.m. | 2 hours, 4 minutes ago
Description : Information disclosure may be there when a guest VM is connected.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21434 - Cisco Wireless LAN Controller Denial of Service Vulnerability

CVE ID : CVE-2025-21434
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21435 - Cisco ASA Internet Explorer Parsing Denial of Service

CVE ID : CVE-2025-21435
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Transient DOS may occur while parsing extended IE in beacon.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21436 - Adobe Flash Memory Corruption Vulnerability

CVE ID : CVE-2025-21436
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21437 - Microsoft Windows Kernel Unmap IOCTL Memory Corruption Vulnerability

CVE ID : CVE-2025-21437
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption while processing memory map or unmap IOCTL operations simultaneously.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21438 - Apache IoT Device Memory Corruption

CVE ID : CVE-2025-21438
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption while IOCTL call is invoked from user-space to read board data.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21439 - Cisco WLAN Driver Heap Buffer Overflow

CVE ID : CVE-2025-21439
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21440 - "TP-Link WLAN Driver Buffer Overflow"

CVE ID : CVE-2025-21440
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21441 - "TP-Link WLAN Driver Out-of-Bounds Write Vulnerability"

CVE ID : CVE-2025-21441
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21442 - Apache HTTP Server Buffer Overflow

CVE ID : CVE-2025-21442
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption while transmitting packet mapping information with invalid header payload size.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21443 - Cisco eAVB Heap Buffer Overflow

CVE ID : CVE-2025-21443
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption while processing message content in eAVB.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21447 - Cisco Router Device IO Control Session Control Memory Corruption

CVE ID : CVE-2025-21447
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Memory corruption may occur while processing device IO control call for session control.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-21448 - Cisco Wireless Router Denial of Service

CVE ID : CVE-2025-21448
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : Transient DOS may occur while parsing SSID in action frames.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3348 - Code-projects Patient Record Management System SQL Injection Vulnerability

CVE ID : CVE-2025-3348
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /edit_dpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3349 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3349
Published : April 7, 2025, 11:15 a.m. | 2 hours, 3 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30373 - Graylog HTTP Input Authentication Bypass Vulnerability

CVE ID : CVE-2025-30373
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...