CVE tracker
363 subscribers
4.95K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-40624 - TCMAN's GIM SQL Injection Vulnerability

CVE ID : CVE-2025-40624
Published : May 6, 2025, 11:15 a.m. | 3 hours, 34 minutes ago
Description : SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ and “email” parameters of the ‘updatePassword’ endpoint.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-40625 - TCMAN GIM Unauthenticated File Upload RCE

CVE ID : CVE-2025-40625
Published : May 6, 2025, 11:15 a.m. | 3 hours, 34 minutes ago
Description : Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4347 - D-Link DIR-600L Critical FormWlSiteSurvey Buffer Overflow Vulnerability

CVE ID : CVE-2025-4347
Published : May 6, 2025, 11:15 a.m. | 3 hours, 34 minutes ago
Description : A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been declared as critical. Affected by this vulnerability is the function formWlSiteSurvey. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4348 - D-Link DIR-600L L2TP Buffer Overflow

CVE ID : CVE-2025-4348
Published : May 6, 2025, 11:15 a.m. | 3 hours, 34 minutes ago
Description : A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been rated as critical. Affected by this issue is the function formSetWanL2TP. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0984 - Netoloji Software E-Flow Cross-site Scripting (XSS) and File Content Injection Vulnerability

CVE ID : CVE-2025-0984
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netoloji Software E-Flow allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS, File Content Injection.This issue affects E-Flow: before 3.23.00.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4349 - "Critical Command Injection in D-Link DIR-600L"

CVE ID : CVE-2025-4349
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the argument host leads to command injection. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4350 - D-Link DIR-600L Wake-on-LAN Command Injection Vulnerability

CVE ID : CVE-2025-4350
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host leads to command injection. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4352 - Golden Link Secondary System SQL Injection Vulnerability

CVE ID : CVE-2025-4352
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, has been found in Golden Link Secondary System up to 20250424. This issue affects some unknown processing of the file /reprotframework/tcEntrFlowSelect.htm. The manipulation of the argument custTradeId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4353 - Golden Link Secondary System SQL Injection Vulnerability

CVE ID : CVE-2025-4353
Published : May 6, 2025, 12:15 p.m. | 2 hours, 34 minutes ago
Description : A vulnerability, which was classified as critical, was found in Golden Link Secondary System up to 20250424. Affected is an unknown function of the file /paraframework/queryTsDictionaryType.htm. The manipulation of the argument dictCn1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2018-1359 - Apache HTTP Server Authentication Bypass

CVE ID : CVE-2018-1359
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : Rejected reason: Not used
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4354 - Tenda DAP-1520 Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-4354
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02 and classified as critical. Affected by this issue is the function check_dws_cookie of the file /storage. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4355 - Tenda DAP-1520 Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-4355
Published : May 6, 2025, 1:15 p.m. | 1 hour, 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been classified as critical. This affects the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4356 - Tenda DAP-1520 Stack-Based Buffer Overflow in Authentication Handler

CVE ID : CVE-2025-4356
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been declared as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4357 - Tenda RX3 Command Injection Vulnerability

CVE ID : CVE-2025-4357
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4358 - PHPGurukul Company Visitor Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4358
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4359 - iSourcecode Gym Management System SQL Injection Vulnerability

CVE ID : CVE-2025-4359
Published : May 6, 2025, 2:15 p.m. | 34 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22479 - Dell Storage Center - Dell Storage Manager Path Traversal Vulnerability

CVE ID : CVE-2025-22479
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23379 - Dell Storage Center - Dell Storage Manager Cross-site Scripting

CVE ID : CVE-2025-23379
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45487 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45487
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45488 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45488
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-45489 - Linksys E5600 Command Injection Vulnerability

CVE ID : CVE-2025-45489
Published : May 6, 2025, 4:15 p.m. | 2 hours, 34 minutes ago
Description : Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...